IDS mailing list archives

Full Packet Capture - User Requirements


From: "Andy Cuff" <lists () securitywizardry com>
Date: Fri, 16 Jul 2004 13:15:48 +0100

Hi,
I was wondering whether anyone had explored the creation of The User
Requirements for a Full Packet Capture Capability.
Looking at things such as
Duration of Retention separating both headers and Data
Bandwidth issues surrounding remote collation
Streams
Unique Selling Points
etc etc
I will tackle presentation through a protocol analyser separately, though it
is relevant in how the raw packet capture is stored.

Solutions will be tackled on a separate subject heading in order to
differentiate between the 2

cheers in advance
-andy
Talisker Security Tools Directory
http://www.securitywizardry.com


--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE
IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------


Current thread: