All of lore.kernel.org
 help / color / mirror / Atom feed
* Open source firewalls
@ 2005-07-13 16:34 Vinay Venkataraghavan
  2005-07-13 16:47 ` Alejandro Bonilla
                   ` (2 more replies)
  0 siblings, 3 replies; 19+ messages in thread
From: Vinay Venkataraghavan @ 2005-07-13 16:34 UTC (permalink / raw)
  To: linux-crypto; +Cc: linux-kernel

Hello,

I have implemented an bare bones Intrusion detection
system that currently detects scans like open, bouce,
half open etc and a host of other tcp scans.

I would like to develop this into a full blown IDS
which is capable of detecting buffer overflow attacks,
sql injection etc. 

I know how to implement buffer overflow attacks. But
how would an intrusion detection system detect a
buffer overflow attack. My question is at the layer
that the intrusion detection system operates, how will
it know that a particular string for exmaple is liable
to overflow a vulnerable buffer. 

Are there other open source firewall implementations
other than snort?

I would apprecitate it if you could let me know.
Thanks,
Vinay



		
__________________________________ 
Do you Yahoo!? 
Yahoo! Mail - Find what you need with new enhanced search. 
http://info.mail.yahoo.com/mail_250

^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2005-07-15 11:29 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-07-13 16:34 Open source firewalls Vinay Venkataraghavan
2005-07-13 16:47 ` Alejandro Bonilla
2005-07-13 17:00   ` Maciej Soltysiak
2005-07-13 17:04 ` Nigel Rantor
2005-07-14 10:13 ` Helge Hafting
2005-07-14 10:24   ` RVK
2005-07-14 12:20     ` Helge Hafting
2005-07-14 12:20       ` RVK
2005-07-14 13:06         ` Helge Hafting
2005-07-14 14:04           ` RVK
2005-07-14 22:53         ` Buffer Over-runs, was " Brian O'Mahoney
2005-07-15  6:41           ` RVK
2005-07-15  6:51             ` Arjan van de Ven
2005-07-15  8:26               ` RVK
2005-07-15  8:46                 ` Arjan van de Ven
2005-07-15  9:28                   ` RVK
2005-07-15  9:29                   ` RVK
2005-07-15 11:17                   ` RVK
2005-07-15 11:24                     ` Arjan van de Ven

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.