Statistical-Based Intrusion Detection
Hey peeps. I got this off of the focus-ms list today coincidentally after I had begun reading the article on the Security Focus site. I figured you guys may be interested.
While I haven't yet finished reading the article in its entirety, I am already forming somewhat of an opinion of its subject matter. I can't say that I see much value that a tool of this nature would add to my network. The way I see it, the most common place something like this would be used is in a Web DMZ or something along those lines. However, how stable is a web environment in regards to normal traffic load. The workload could vary greatly, depending on the day, hour, publicity of the website(s), and many other factors. Now, I am probably being a little premature in forming my opinion, so I will leave it at that. Maybe I can get some sort of an evaluation of the tool at hand so that I can form a more educated opinion. I am, however, interested in hearing what you guys think.
Quote:
Statistical-Based Intrusion Detection
By Jamil Farshchi
This article will examine statistical-based intrusion detection systems, which alert on anomalous network behaviour, thus providing better monitoring for zero-day exploits than traditional IDS.
http://www.securityfocus.com/infocus/1686
Marc Fossi
Symantec Corp.
www.symantec.com
I think the author says it best here:
Quote:
Conclusion
There is still no IDS silver bullet. The best solution seems to be a combination of IDS approaches. There are a few vendors that offer the SBID system solution today. Fortunately, these solutions are all part of a larger offering that includes a RBID system. Rest assured, there will be bigger and badder worms than W32.SQLExp - in today's world of cyber-crime, malicious users, and cyber-terrorism, threats will undoubtedly continue to evolve and test security professionals. With the implementation of a statical-based intrusion detection system in addition to a rule-based system, though, you will be better protected against current and future threats. And maybe with the enhanced security on your network, you will be able to spend more time with your dog and less with a worm.
Regards,
t2k2