Network Security Consulting Agency Since 1989 - Specialized in Unix, Windows, TCP/IP and Internet
You are here
:
Home
>
Resources
>
Lectures
> Intrusion detection with Shadow
Go to:
HSC Trainings
Search
:
Services
Skills & Expertise
Consulting
ISO 27001 services
Vulnerabilities monitoring
Audit & Assessment
Penetration tests
Vunerability assessment (TSAR)
Forensics
ARJEL
Training courses
E-learning
Conferences
Agenda
Past events
Tutorials
Resources
Thematic index
Tips
Lectures
Courses
Articles
Tools (download)
Vulnerability watch
Company
Hervé Schauer
Team
Job opportunities
Credentials
History
Partnerships
Associations
Press and
communication
HSC Newsletter
Press review
Press releases
Publications
Contacts
How to reach us
Specific inquiries
Directions to our office
Hotels near our office
Intrusion detection with Shadow
Access to the content
Beginning of the presentation
Description
Presentation of the Shadow (CIDER) intrusion detection tool from the Navy.
Context & Dates
Talk made before the
SUR group from the OSSIR
, on 6 July 1999.
Author
Tristan Debeaupuis
Type
33 slides [
-
]
Abstract &
Table of content
Flyleaf
Introduction
Plan
Introduction
Organisation de la mise en place
Limites sans IDS
SHADOW : le nécessaire
Vue globale de l'architecture
Architecture mise en place
SHADOW est un atelier
Pourquoi TCPdump ?
Type d'IDS
Proposition d'architecture
Téléchargement du logiciel
Mettre en place un senseur
Mettre en place la station d'analyse
Les filtres
Un filtre IMAP
Un filtre NFS et la sortie
C'est facile
Affiner un filtre
Le filtre Core_Hosts
Filtre serveur Web Core_Host Filter
Filtre Core_Host pour les serveurs Web Interpretation
Filtre Bad_Events
Filtre Bad_Hosts
Filtres ... fin
Affichage
Affichage
Affichage sur le long terme
Affichage sur le long terme
Ce qu'il vous reste à faire
Mise en place du modèle optimal
Conclusion
Related documents
Intrusion Detection
Argus
[19 February 2002 -
]
Advanced Intrusion Detection
Encrypting hostile Web content over HTTP
[31 May 2007 -
]
Intrusion Prevention : New reinforcement tools for perimetric defense
[16 June 2005 -
]
Generation of regular expressions from logged events
[2 February 2005 -
]
Intrusion detection and network forensic
[6 May 2004 -
]
Intrusion Detection
[25 September 2002 -
]
Advanced Intrusion Detection Environment (AIDE)
[9 January 2002 -
]
Follow-up on discovering the libnids
[6 September 2001 -
]
Introduction to the libnids
[13 April 2001 -
]
rkscan tool
[Rootkit scanner for loadable kernel-module rootkits -
]
RKSCAN: Scanner for loadable kernel-module rootkits
[25 October 2000 -
]
Presentation and detection of the ADORE rootkit
[16 October 2000 -
]
IDSwakeup tool
[Test of intrusion detection systems -
]
Round table on intrusion detection
[8 June 2000 -
]
Technical method to evade intrusion detection system.
[27 March 2000 -
]
Help to detect attack, intrusion and anomaly.
[27 March 2000 -
]
Introduction to intrusion detection
[26 January 2000 -
]
Presentation of some free software for intrusion detection
[26 January 2000 -
]
Copyright
© 1999, Hervé Schauer Consultants, all rights reserved.
Last modified on 22 April 2002 at 15:08:40 CET - webmaster@hsc.fr
Information on this server
- © 1989-2010 Hervé Schauer Consultants