Results 1 to 3 of 3

Thread: SBID: Some Information

  1. #1

    Lightbulb SBID: Some Information

    To stop the Intrusions? It changes Method....



    I have read an article on a monthly (Hacker Italia) that quoted: " Soon the system to notice the intrusions denominated as Statistical or Behaviour Based it would be able to blow away the most diffused Signature Based "
    This Why?
    If the answer can interest you I give it for you immediately:
    the biggest problem of these traditional systems, based on a system of signatures and rules, it is the speed of compilation of the same signatures, without which the system shows itself blind. To include in the list an attack, in fact it needs to individualize it, to record it and to analyze it.
    Then it it is necessary to look for the rule in the intern of some signatures and to distribute the signatures themselves.
    The Statistical Based Intrusion Detection (SBID) they have a whole other philosophy instead.
    In few words once determined the normal activity of the system all of this that goes out of the parameters of the norm it is considered as suspicious activity. The SBID continually analyze the normal traffic of the net in which they are directly implemented with a proportional precision to the period of activity of the same IDS. For this reason they don't serve continuous updatings of the signatures of identification and in comparison to the traditional systems they guarantee greater coverage to the new typologies of attack.

    I hope to be you useful........

    See Ya.

    Anatra.

  2. #2
    Just a Virtualized Geek MrLinus's Avatar
    Join Date
    Sep 2001
    Location
    Redondo Beach, CA
    Posts
    7,323
    **Moved from Tutorials to IDs & Scanner Discussions** (not really a tutorial)

    More info on SBID can be found here

    Other sources/references of information:

    http://www.sans.org/resources/idfaq/statistic_ids.php
    http://www.linuxsecurity.com/article...icle-7109.html
    Goodbye, Mittens (1992-2008). My pillow will be cold without your purring beside my head
    Extra! Extra! Get your FREE copy of Insight Newsletter||MsMittens' HomePage

  3. #3
    Thank you and sorry for the Mistake MsMittens
    cee Ya

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •