Focus on IDS Mode:
(Page 20 of 199)  < Prev  15 16 17 18 19 20 21 22 23 24 25  Next >
Host Based IDS 2008-10-20
Security Group (secgro gmail com) (2 replies)
Hello,

I am currently evaluating several host-based Intrusion Detection
Systems to monitor servers in a DMZ. My company only wants to monitor
for suspecious behaviour on critical servers, without the need for a
company wide security system. I am not interested in a network-bases
ids because this is

[ more ]  [ reply ]
Re: Host Based IDS 2008-10-20
Erik Harrison (eharrison gmail com)
Re: Host Based IDS 2008-10-20
Stefano Zanero (s zanero securenetwork it)
Re: Looking for a thesis topic in the area of IDS 2008-10-05
zubair shafiq yahoo com (1 replies)
Botnet detection is a very hot topic. But it is very difficult to get hold of any network traces for experimentation.

Recently Gu has done the first thesis on Botnet at Georgia Tech.

------------------------------------------------------------------------

Test Your IDS

Is your IDS deployed corre

[ more ]  [ reply ]
Re: Looking for a thesis topic in the area of IDS 2008-10-06
\Zow\ Terry Brugger (zow acm org)
Looking for a thesis topic in the area of IDS 2008-10-03
saintarmin hotmail com
Hi !!!

I am looking for a thesis topic in the area of IDS any ideas, any help would be greatly appreciated

thanks so much

------------------------------------------------------------------------

Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with re

[ more ]  [ reply ]
Picviz 0.3 released 2008-09-20
Sebastien Tricaud (stricaud inl fr)
Picviz 'good coffee' 0.3 is *out*.
...to have a good coffee, we must filter it!

What is Picviz ?
================

Picviz is a parallel coordinates plotter, written to help people
finding a needle in a haystack when dealing with numerous events
on their system and struggling to maintain an acceptab

[ more ]  [ reply ]
Re: OSSEC HIDS v1.6 released 2008-09-05
contact fingers gmail com
Hey,

I was just curious. OSSEC is doing an awesome job. Isn't it bought by Third Brigade. How does open source work when someone bought a project. Was just wondering how it works out.

Anu

------------------------------------------------------------------------

Test Your IDS

Is your IDS deployed

[ more ]  [ reply ]
[Tool] Distack framework for attack detection and traffic analysis 2008-09-03
Christoph Mayer (mayer tm uka de)
Hi,

I am pleased to announce the Open Source release of "Distack"

*** http://www.tm.uka.de/distack ***

Distack is a framework for local and distributed attack detection and
traffic analysis. It can run on live interfaces or traces files, as well
as in simulation environments. Therefore it p

[ more ]  [ reply ]
OSSEC HIDS v1.6 released 2008-09-02
dcid ossec net
The OSSEC team is pleased to announce the general availability of OSSEC version 1.6.

OSSEC is an Open Source Host-based Intrusion Detection System. It performs log analysis, integrity checking, Windows registry monitoring,
rootkit detection, real-time alerting and active response. It runs on most o

[ more ]  [ reply ]
[Suspected Spam]Security Assessment of the Internet Protocol 2008-08-25
Fernando Gont (fernando gont com ar)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello, folks,

The United Kingdom's Centre for the Protection of National Infrastructure
has just released the document "Security Assessment of the Internet
Protocol", on which I have had the pleasure to work during the last year or
so.

The motivatio

[ more ]  [ reply ]
RE: Talisker Site Returns - Rate/Review IDS Now 2008-08-18
Andy Cuff (Talisker) (SecurityLists securitywizardry com) (1 replies)
Hi Mohamed,
Reviewing the products is currently available and the more popular products
appear higher in the listings. The problem is finding people willing to
share their feelings on the various products, or add new listings.

I've even resorted to bribing them with a free T-Shirt for the best rev

[ more ]  [ reply ]
RE: Talisker Site Returns - Rate/Review IDS Now 2008-08-18
Mohamed Farid (m farid shawara gmail com)
Talisker Site Returns - Rate/Review IDS Now 2008-08-11
Andy Cuff (Talisker) (SecurityLists securitywizardry com) (1 replies)

Morning, (We are not a vendor, We do not resell products

Thanks to Michele Jordan for doing all the hard work!

Our vendor neutral site has been providing salient detail on every single
Information Security product (good, bad or ugly) since 1999. The effort in
updating the content is both time c

[ more ]  [ reply ]
RE: Talisker Site Returns - Rate/Review IDS Now 2008-08-17
Mohamed Farid (m farid shawara gmail com)
OSSEC vs Samhain HIDS discussion 2008-08-10
Mattieu Puel (vodmat news gmail com)
Hi all,
I am looking forward a HIDS for mass deployment on unices systems (~= 1200
Linux/Solaris/AIX). I need a centralized system (in order to simplify
administration), excluding tripwire/aide/integrit and the like..

A that point of my researches, I have the feeling that OSSEC or Samhain
would be

[ more ]  [ reply ]
ArpON detecs and block Arp Poisoning/Spoofing attacks 2008-08-02
Andrea Di Pasquale (spikey it gmail com)
Hi,
My name is Andrea Di Pasquale and I study at Secondary High School
"S. Quasimodo"
in Catania, Italy.

Some time ago I released a research project related to the security
of the
address resolution protocol Arp, the project name being Arpon (Arp
handler
inspection).

Arpon makes the protocol

[ more ]  [ reply ]
ICSA Labs releasing white papers 2008-07-24
Walsh, John (Jack) (jwalsh icsalabs com)
Focus-IDS Readers:

The network IPS team at ICSA Labs announced recently on our RSS feed
(http://feeds.feedburner.com/icsalabsnetworkips) that we'd be publishing
a couple new white papers in successive weeks. The first paper posted
earlier today introduces readers to the distinguishing features of

[ more ]  [ reply ]
NSS Labs Conducting 10 Gbps IPS Group Test 2008-07-18
rmoy nsslabs com


IPS users, we at NSS Labs are conducting a 10Gbps IPS group test. True 10Gbps appliances and stacked & switched solutions are being evaluated.

The IPS test criteria is posted here:

http://nsslabs.com/certification-criteria/ips

We are interested in your requirements and experiences as users

[ more ]  [ reply ]
Re: Re: Remote File include (RFI) vulnerabilities 2008-07-17
aditya mukadam gmail com

It all depends on company's policies and procedure , on which traffic to monitor. Ideally, we should be monitoring incoming & outgoing traffic. This is not only true for RFI but for other signatures/exploits/ etc as well. T

Thanks,
Aditya Govind Mukadam

-------------------------------------------

[ more ]  [ reply ]
DNS Cache Poisoning attack 2008-07-17
Ravi Chunduru (ravi is chunduru gmail com) (2 replies)
Does anybody have snort or Intrupro-IPS signature(s) to detect DNS
Cache Poisoning attack?
Also, is there any PoC to simulate the attack and test the
effectiveness of signature(s)?

thanks
Ravi

------------------------------------------------------------------------

Test Your IDS

Is your IDS deplo

[ more ]  [ reply ]
Re: DNS Cache Poisoning attack 2008-07-18
Mario A. Spinthiras (mario blupenguin com)
Re: DNS Cache Poisoning attack 2008-07-17
Joel Esler (joel esler mac com) (1 replies)
Re: DNS Cache Poisoning attack 2008-07-18
Michael Rash (mbr cipherdyne org) (1 replies)
Re: DNS Cache Poisoning attack 2008-07-21
Secure Scorp (securescorp gmail com)
Remote File include (RFI) vulnerabilities 2008-07-16
Ravi Chunduru (ravi is chunduru gmail com) (1 replies)
Hi,

I am using IntruPro-IPS to protect both servers and clients. It seems
to be flagging RFI related anomalies for traffic going from internal
clients to servers in Internet. I thought these attacks need to be
detected only if the internal servers are being attacked. That is, I
think that RFI d

[ more ]  [ reply ]
Re: Remote File include (RFI) vulnerabilities 2008-07-17
Jamie Riden (jamie riden gmail com)
(Page 20 of 199)  < Prev  15 16 17 18 19 20 21 22 23 24 25  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus