OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
intrusion detection system

From: Tomas Pluskal (plusikpohoda.cz)
Date: Mon Oct 18 2004 - 08:18:31 CDT


Hello to all,

I have implemented a new type of intrusion detection system for my Master
thesis. I would like to announce this information, in case anyone would be
interested in this research.

The IDS system is designed as a kernel module for FreeBSD 5.2. It is
inspired by the SpamAssassin program, which detects spam by applying a set
of tests to every email message and counting a sum of point score
generated by each test. My IDS system applies a set of tests to every
running process in the OS and counts its score generated by the tests.
Therefore, the purpose of the IDS is not to monitor the network traffic,
but rather to monitor the process activity.

The current system status is a "working prototype" - it is more a research
than a real IDS.

If you are interested in this, please read the details here:
http://plusik.pohoda.cz/thesis/

Thanks,

Tomas
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"