IDS mailing list archives

number of attacks signature


From: "average coder" <averagecoder () gmail com>
Date: Wed, 10 May 2006 16:53:28 +0800

Dear All,

I am interested in ids. I've installed snort system and its default
signature  (the one downloaded from the site).

I've found out, within its signatures, ip source and ip destination
fields consists of a few variants only. Namely, it's either, internal
network, external network and some other exceptions.

I am curious whether it's the trends in enterprise system also? Is it
true that comparing to router, the prefixes in routing table consists
of more entries? (especially backbone)

Besides that, roughly , how many signatures are there in enterprise ids?

thank you

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------


Current thread: