|
|||||||||||
|
RE: IDS Informer
From: Brian Laing <Brian.Laing(at)Blade-Software.com>
Date: Thu Nov 21 2002 - 16:09:53 EST
-----BEGIN PGP SIGNED MESSAGE-----
Brian, Been awhile since I sent this out and I can not recreate my thought pattern on this one. That being said what we inject on the wire is an actual attack, however we don't establish a connection to the target. Given that we do not make this connection (although the packets as if it did are injected on the wire along with the attack), the attack does not harm the targeted machine. So what the IDS sees is the actual attack it just has no effect on the machine. Additionally we have just release a major update to our attack library in IDS informer. Now all exploits have both a successful and an unsuccessful version. Now our customers can inject each individually onto the wire and see how their IDS de jour handles the different traffic. This can also be used by IDS vendors to test signatures that detect each as a different state. If you would like to chat in more detail I would be happy to have a phone call with you or anyone else that would like to discuss our attack library. Additionally if you are an IDS vendor who we are not working with we do offer direct access to our library of Exploit code, and other information that has been found useful to the IDS vendors we are working with.
Cheers,
On Tue, Oct 08, 2002 at 07:41:33AM -0700, Brian Laing wrote:
So can you explain how this is a valid test of an IDS?
Many IDSs claim they check the differences between an failed attack
and a
-----BEGIN PGP SIGNATURE-----
iQA/AwUBPd1F5YcqkwDZV2C0EQK0RgCfRTx2r9RE7yvPQftWCd/D+lKL/1cAn3oo
+f5EgM2iGgXSpwzGjJGLTQd7
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT |
||||||||||
|
|||||||||||