|
|
Choosing A Webhost: |
Re: Rule Load Formula: msg#00099security.ids.snort.bleedingsnort
Something I've considered doing before and found to be more work that IThis would indeed be very interesting. Even if, in the end, you determined that the performance numbers you get out of this "average" traffic were marginally reliable at best, having a large body of sample traffic to test rules with would be exceedingly helpful in a lot of circumstances. I would think that you'd want constant additions to the pool of PCAPs, so that you get a better sample of the real world, and so that you don't fall into traps based on the type of traffic you once collected and have been using for some time. I think the biggest obstacle to something like this isn't even so much time as it is privacy. I could sit around and collect PCAPs on some of my personal and/or work boxes all day long, but I'd have to sift through them to remove private e-mail text, any cleartext-submitted passwords, etc. that I didn't want the rest of the universe to see. More imporantly, I'd feel like I needed the consent of everyone whose traffic I captured before publishing a PCAP. Got any thoughts on this angle of such a collection? Alex Kirk
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Rule Load Formula, Alex Kirk |
|---|---|
| Next by Date: | Adobe Sigs, Matt Jonkman |
| Previous by Thread: | Re: Rule Load Formula, Sushant Sinha |
| Next by Thread: | Re: Rule Load Formula, Martin Holste |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |