Slashdot Log In
OpenBSD Gains "Fuzzy" User Profiling IDS
Posted by
timothy
on Tue Dec 09, 2003 09:15 PM
from the and-who-the-hell-are-you dept.
from the and-who-the-hell-are-you dept.
NaveWeiss writes "According to the OpenBSD Journal, major work has been done on an innovative new OpenBSD feature termed 'fuzzy user profile' intrusion detection system' - or 'fupids.' According to Steffen Wendzel, the code 'creates profiles for every user who does an execve() syscall on obsd systems.'"
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Re:Link? (Score:4, Informative)
Oh, it really is hard to click on the link on the linked page, or, even worse, search Google for FUPIDS and find the page in, as he puts it, "my poor English" [doomed-reality.org]. Pretty sparse on details when you get to it anyhow. Use the source, Luke.
Parent
Courtest of Babelfish (Score:4, Informative)
babelfish. [altavista.com]
Re:Courtest of Babelfish (Score:2)
Re:Courtest of Babelfish (Score:2, Informative)
Re:Courtest of Babelfish (Score:1)
Re:Courtest of Babelfish (Score:1)
German: ueber wachungs strategien
English: over watching strategy
(Latin-ish: super visio strategy)
Yay for germanic languages!
Yes, you are right (Score:1)
...noexec/ro on partitions... (Score:5, Interesting)
Re:...noexec/ro on partitions... (Score:3, Interesting)
Re:...noexec/ro on partitions... (Score:1, Funny)
Re:...noexec/ro on partitions... (Score:1, Troll)
Re:...noexec/ro on partitions... (Score:3, Interesting)
Taking this a step further, if it was not for the performance problem, could you not just put the executables on a CD (in a read-only drive of course), which could be updated only by having physical access, and a suitably equipped PC with writer to t
Does it log activity? (Score:4, Interesting)
He mentions that it sets a threshhold of user activity, such as using too many new programs within a limited space of time.
Any indication that it does some sort of observation of user activity (think bayesian learning for spam filters) to build profiles which, if exceeded by too high a metric within too short a time, would also trigger a log error?
Fupids is not in OpenBSD's tree (Score:4, Informative)
This is not true. Fupids is work by a single person, who is not an OpenBSD developer. At this point in time, nothing suggests it will be put into the OpenBSD tree.
NOT in the tree (Score:2, Informative)
Re:BSD for Windows XP? (Score:2, Funny)
Re:BSD for Windows XP? (Score:1)
Re:BSD for Windows XP? (Score:1)