« What is Zero Day protection? | Main | Your private threat-detector »

October 27, 2005

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8347fd15c69e200d83495618a69e2

Listed below are links to weblogs that reference Of butterflies and raindrops...:

Comments

MP

I enjoyed this posting very much. My question regarding anomoly detection is this. If you were to develop/deploy a system for anomoly detection in a network (be it for something like IDS or QoS or whatever) you would have to assume that at the time of deployment, your network was acting "normal" and use that as your baseline for detecting anomolies. What if your network already contained something it shouldn't or acted in a way it shouldn't? This would contaminate the baseline and the anomoly detection "tool" would consider this normal, right? So at what point of the life cycle of a network is it appropriate to install something that does anomoly detection? Does anomoly detection need to run parallel to something that does signature based review? OK, that was more than one question. Again, a nice article which I enjoyed.

Juergen Brendel

Thank you for the feedback on the article, and sorry for the late reply.
You bring up a very good point: If you have a baselining anomaly detection system, then you need very clean traffic conditions during this baselining phase. That, and other reasons, have compelled us to design an anomaly detection solution, which does not rely on baselines at all. For more information about this, see my blog entries here (http://esphion.blogs.com/esphion/2005/10/anomaly_detecti.html) and here (http://esphion.blogs.com/esphion/2005/07/anomaly_detecti.html).

As a result, our solution is more dynamic than any baselining solution. Even if during first deployment an anomaly might be in full swing, our system would not 'learn' this as normal. If the anomaly is present when our solution first gets a look at that network, then it might not alert to it. However, once the anomaly stops, and starts again, we would detected it.

In the moment you start to use baselines, you begin to rely on prior knowledge. And once that happens, you are more prone to false positives, or the kinds of problems you have mentioned.

Juergen

sjsmvkmcfy

reality sex stories

North Face Sale

fighting spirit is extremely tenacious vitality of a master, and now at the most negative situation must lie in bed during the first half, but also a jump.

cheap north face

Incredible as this may sound, such is the behavior of highly complex, dynamic systems: Changing just a single parameter may eventually result in a completely different and unexpected outcome http://www.northface4sale.org

Marc Jacobs  handbags

This is a very popular brand of products accepted by the public and welcome!

The comments to this entry are closed.