IDS mailing list archives
Re: Snort with an expert system
From: Stefano Zanero <s.zanero () securenetwork it>
Date: Thu, 25 Jun 2009 12:26:07 +0200
"A false positive is an alert that triggers on normal traffic where no intrusion or attack is underway"
That's a good definition, but not really complete. Under that definition, if you place a rule that flags IRC connections, and it fires, is that a false positive? Is it a false positive a case where there is no rule, or the traffic does not match with the rule, and the engine still fires? Is it a false positive a case where a rule correctly matches, but the user didn't want to be alerted to that traffic ?
In addition, I don't understand why there would be no reason that this algorithm would work. Could you explain? The algorithm is developed by experts in Bayesian statistics and has been applied in other fields as well.
The algorithm type has apparently no relevance to the problem. Why should a false positive be statistically different, in the sense you are considering, from a true positive? Best, Stefano ----------------------------------------------------------------- Securing Your Online Data Transfer with SSL. A guide to understanding SSL certificates, how they operate and their application. By making use of an SSL certificate on your web server, you can securely collect sensitive information online, and increase business by giving your customers confidence that their transactions are safe. http://www.dinclinx.com/Redirect.aspx?36;5001;25;1371;0;1;946;9a80e04e1a17f194
Current thread:
- Re: Re: Snort with an expert system tol (Jun 23)
- Re: Snort with an expert system Stefano Zanero (Jun 25)
- Re: Snort with an expert system Tomas Olsson (Jun 25)
- Re: Snort with an expert system Stefano Zanero (Jun 25)
- Re: Snort with an expert system Tomas Olsson (Jun 25)
- Re: Snort with an expert system Stefano Zanero (Jun 25)
- Re: Snort with an expert system Tomas Olsson (Jun 25)
- Re: Snort with an expert system Stefano Zanero (Jun 25)
- Re: Snort with an expert system Tomas Olsson (Jun 25)
- Re: Snort with an expert system Joel Esler (Jun 25)
- Re: Snort with an expert system Greg Shipley (Jun 25)
- Re: Snort with an expert system Martin Roesch (Jun 25)
- Re: Snort with an expert system Gary Halleen (Jun 26)
- Re: Snort with an expert system Stefano Zanero (Jun 26)
- Re: Snort with an expert system mhellman (Jun 26)
- Re: Snort with an expert system Martin Roesch (Jun 29)
- Re: Snort with an expert system Tomas Olsson (Jun 25)
- Re: Snort with an expert system Stefano Zanero (Jun 25)