OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Composite Patterns
From: Jacob Martinson (jmartinsonAPERIAN.COM)
Date: Tue Nov 28 2000 - 10:11:17 CST


I should clarify, I am wanting to detect UDP floods, not communication
between managers and daemon agents.

-----Original Message-----
From: Jacob Martinson [mailto:jmartinsonAPERIAN.COM]
Sent: Tuesday, November 28, 2000 8:19 AM
To: FOCUS-IDSSECURITYFOCUS.COM
Subject: Composite Patterns

I am trying to find a decent NIDS that can detect fraggle, tfn, trinoo etc.
Snort doesn't do composite patterns at this point and NetRanger requires
that you run OpenView on the management console (as far as I can tell).
Does anyone have any recommendations?

My ultimate goal is something that will alert me as quickly as possible when
we are experiencing a dos attack.

Thanks for any input!

Jacob Martinson

---
BSD Unix - the first operating system with an IP stack.