« What is Zero Day protection? | Main | Your private threat-detector »

October 27, 2005

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8347fd15c69e200d83495618a69e2

Listed below are links to weblogs that reference Of butterflies and raindrops...:

Comments

MP

I enjoyed this posting very much. My question regarding anomoly detection is this. If you were to develop/deploy a system for anomoly detection in a network (be it for something like IDS or QoS or whatever) you would have to assume that at the time of deployment, your network was acting "normal" and use that as your baseline for detecting anomolies. What if your network already contained something it shouldn't or acted in a way it shouldn't? This would contaminate the baseline and the anomoly detection "tool" would consider this normal, right? So at what point of the life cycle of a network is it appropriate to install something that does anomoly detection? Does anomoly detection need to run parallel to something that does signature based review? OK, that was more than one question. Again, a nice article which I enjoyed.

Juergen Brendel

Thank you for the feedback on the article, and sorry for the late reply.
You bring up a very good point: If you have a baselining anomaly detection system, then you need very clean traffic conditions during this baselining phase. That, and other reasons, have compelled us to design an anomaly detection solution, which does not rely on baselines at all. For more information about this, see my blog entries here (http://esphion.blogs.com/esphion/2005/10/anomaly_detecti.html) and here (http://esphion.blogs.com/esphion/2005/07/anomaly_detecti.html).

As a result, our solution is more dynamic than any baselining solution. Even if during first deployment an anomaly might be in full swing, our system would not 'learn' this as normal. If the anomaly is present when our solution first gets a look at that network, then it might not alert to it. However, once the anomaly stops, and starts again, we would detected it.

In the moment you start to use baselines, you begin to rely on prior knowledge. And once that happens, you are more prone to false positives, or the kinds of problems you have mentioned.

Juergen

sjsmvkmcfy

reality sex stories

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment