Why You’re Not Finished Yet

Posted by arlene

You have now taken a close look at Stalker and CMDS —two well-known system level UNIX IDSs. Both tools provide audit reduction but differ in primary focus. CMDS provides some attack pattern analysis, but its strength lies in the statistical anomaly detection techniques for which it is well known. Stalker also provides some statistical threshold […]

Network Sniffers Do Not See All Packets

Posted by arlene

A network IDS works by running a network adapter in promiscuous mode to capture all of the packets coming into and going out of a particular subnet. Notice that this is not the same as watching all of the network traffic that appears on a subnet. Look at Figure 9.2. Here, the physical arrangement of […]

Alexa CounterFeedBurner Counter