IDS Evasion

Marco Ramilli
Date
19 March 2010
Read
Share

Alright folks,
yet another paper has been published so I can finally upgrade my blog with some interesting results.
In 2009 we (Network Security abs @ University of Bologna) studied a new way to analyze attacks using Data Mining over SNMP artificial variables. Artificial means forged by us, over natural SNMP variables.
This pictures show how our approach (we still don't have a name ) reacts to a DOS hidden under "normal traffic".

The described approach can also detect many different attacks utilizing the not intrusive SNMP. SNMP is ubiquitous; it runs on every platforms, from CellPhone to Washing Machines, we don't have to configure IDS, nasty systems or exoteric firewalls; what we need is just analyze SNMP data.
So far we don't have a presentable framework, the current version is in pre-alpha, basically we have a set of scripts which made all the computations. We're looking forward to new students that wanna implement a nice framework. If you are interested on this project (even if you are not a student 😀 ) please contact me.

Marco Ramilli
Date
19 March 2010
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier