3 Jun 2008 19:30
Re: CVE selection for IDS/IPS signature rules
Ravi Chunduru <ravi.is.chunduru <at> gmail.com>
2008-06-03 17:30:44 GMT
2008-06-03 17:30:44 GMT
thank you all for responses. There are some tools such as Karalon, Mu and others. i gather from different tests performed by network world and other certification agencies, these tools are used to test the effectiveness of IDS/IPS devices. if the criteria being followed is not complemented by these test tools, then there could be differences in the test results. I wonder what is the criteria of test case selection by these tool vendors and certification agencies. any comments? Ravi On Mon, Jun 2, 2008 at 11:33 AM, Srinivasa Addepalli <srao <at> intoto.com> wrote: > > You got very good answers from Ron. I try to give some specifics. > > 1. Generic signatures > > There are close to 10000 XSS and SQL injection vulnerabilities (based on > search in www.osvdb.org). Some IPS/IDS vendors, including us, don't create > signatures for each one of them. We are able to cover them using 200+ > signatures which are generic in nature. > > IPS systems having intelligent application detection may cover many buffer > overflow attacks using few signatures. For example, we see many HTTP URL, > HTTP request header/response header field, SMTP/FTP/IMAP/NNTP command buffer > overflow attacks. Many of them can be detected with few signatures without > having to develop rules for each CVE. > > 2. Signature deletion to improve IPS/IDS performance. This is one of the(Continue reading)
RSS Feed