public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* Open source firewalls
@ 2005-07-13 16:34 Vinay Venkataraghavan
  2005-07-13 16:47 ` Alejandro Bonilla
                   ` (2 more replies)
  0 siblings, 3 replies; 19+ messages in thread
From: Vinay Venkataraghavan @ 2005-07-13 16:34 UTC (permalink / raw)
  To: linux-crypto; +Cc: linux-kernel

Hello,

I have implemented an bare bones Intrusion detection
system that currently detects scans like open, bouce,
half open etc and a host of other tcp scans.

I would like to develop this into a full blown IDS
which is capable of detecting buffer overflow attacks,
sql injection etc. 

I know how to implement buffer overflow attacks. But
how would an intrusion detection system detect a
buffer overflow attack. My question is at the layer
that the intrusion detection system operates, how will
it know that a particular string for exmaple is liable
to overflow a vulnerable buffer. 

Are there other open source firewall implementations
other than snort?

I would apprecitate it if you could let me know.
Thanks,
Vinay



		
__________________________________ 
Do you Yahoo!? 
Yahoo! Mail - Find what you need with new enhanced search. 
http://info.mail.yahoo.com/mail_250

^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2005-07-15 11:29 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-07-13 16:34 Open source firewalls Vinay Venkataraghavan
2005-07-13 16:47 ` Alejandro Bonilla
2005-07-13 17:00   ` Maciej Soltysiak
2005-07-13 17:04 ` Nigel Rantor
2005-07-14 10:13 ` Helge Hafting
2005-07-14 10:24   ` RVK
2005-07-14 12:20     ` Helge Hafting
2005-07-14 12:20       ` RVK
2005-07-14 13:06         ` Helge Hafting
2005-07-14 14:04           ` RVK
2005-07-14 22:53         ` Buffer Over-runs, was " Brian O'Mahoney
2005-07-15  6:41           ` RVK
2005-07-15  6:51             ` Arjan van de Ven
2005-07-15  8:26               ` RVK
2005-07-15  8:46                 ` Arjan van de Ven
2005-07-15  9:28                   ` RVK
2005-07-15  9:29                   ` RVK
2005-07-15 11:17                   ` RVK
2005-07-15 11:24                     ` Arjan van de Ven

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox