Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Article Announcement: Statistical-Based Intrusion Detection

From: Dongen, Jeroen van <jvandongen(at)seneca.nl>
Date: Tue Apr 22 2003 - 08:26:31 EDT


Nice - however you don't need any kind of IDS to stop something like Slammer IMHO. You need management that give their people the resources to waste half a brain cell and recognise that their database might not necessarily have to be reachable by any other system than the clients they're serving - i.e. simple portfiltering does the trick, both inbound AND outbound traffic that is. Rigorous deployment of (statefull) egress filters would stop a worm like Slammer (or Code Red or Nimda or Slapper or ..., as well as almost any reverse shell-based attack) mostly dead in their tracks.

-Jeroen

-----Original Message-----

From: Marc Fossi [mailto:mfossi@securityfocus.com] Sent: Monday, April 21, 2003 6:12 PM
To: Focus-Virus
Subject: Article Announcement: Statistical-Based Intrusion Detection

Statistical-Based Intrusion Detection
By Jamil Farshchi

This article will examine statistical-based intrusion detection systems, which alert on anomalous network behaviour, thus providing better monitoring for zero-day exploits than traditional IDS.

http://www.securityfocus.com/infocus/1686

Marc Fossi
Symantec Corp.
www.symantec.com



Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the world's premier event for IT and network security experts. The two-day Training features 6 hand-on courses on May 12-13 taught by professionals. The two-day Briefings on May 14-15 features 24 top speakers with no vendor sales pitches. Deadline for the best rates is April 25. Register today to ensure your place. http://www.securityfocus.com/BlackHat-focus-virus


Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the world's premier event for IT and network security experts. The two-day Training features 6 hand-on courses on May 12-13 taught by professionals. The two-day Briefings on May 14-15 features 24 top speakers with no vendor sales pitches. Deadline for the best rates is April 25. Register today to ensure your place. http://www.securityfocus.com/BlackHat-focus-virus
Received on Tue Apr 22 13:24:58 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:39 EDT

Do you need help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library