Snort mailing list archives
Anomaly detection and Snort
From: "Mike DeGraw-Bertsch" <Michael.DeGraw-Bertsch () counterstorm com>
Date: Thu, 12 Apr 2007 15:15:32 -0400
Howdy, My company, CounterStorm, has developed packet content level anomaly detection for the security space. The technology builds statistical models of the contents of network traffic, and looks for anomalies within this. It's distinctly different from most AD technology in that it's actually working on layer 7, not just looking at traffic volumes. We're considering making this available as a Snort module. There are two components that we're considering. The first is what we're calling the confidence module. This module generates a statistical baseline of the network traffic content. It then compares the packets that trigger Snort events to the baseline, and assigns a confidence score to the events. This allows one to triage events, looking at the most anomalous events first. You can almost think of it as signature validation--normal traffic triggering a false positive would get a low priority score, while an actual attack, perhaps with a noop sled, would get a high confidence score. The second component is more straightforward, doing pure detection of anomalous events on the network. This is geared towards detecting crimeware and targeted attacks. Examples of what it can detect include botnet traffic running over port 80, and SQL injection attacks. My biggest question, of course, is if these modules sound useful to you? Almost as big are questions around implementation. We've considered using the priority field as the spot we put the confidence scores; does that make sense? Is there anywhere you'd rather see it? Also, how would you like to see these modules enabled? Per port? Per rule? I've been pretty broad, so I'm also very interested in your questions as well. Thanks, -Mike Mike DeGraw-Bertsch Product Manager CounterStorm, Inc. P: 212-206-1900 x246 mbertsch () counterstorm com ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys-and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Anomaly detection and Snort Mike DeGraw-Bertsch (Apr 12)
- Re: Anomaly detection and Snort David J. Bianco (Apr 12)
- Re: Anomaly detection and Snort Mike DeGraw-Bertsch (Apr 13)
- Re: Anomaly detection and Snort Nikns Siankin (Apr 13)
- Re: Anomaly detection and Snort Mike DeGraw-Bertsch (Apr 13)
- Re: Anomaly detection and Snort David J. Bianco (Apr 12)