<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Real time threat detection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453138#M99274</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, that was a cool link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it didnt show any information on attack progress, stages of attack and alert pattern that normal Cisco IDS will generate for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for deep analytical information, which will show me how to correlate alerts manually. I am using netForensics, I want to make rules in it for IDS and PIX using my understanding to find attack at its point of progress.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Kapish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 Jun 2005 01:20:00 GMT</pubDate>
    <dc:creator>kapishmohole.cisco</dc:creator>
    <dc:date>2005-06-11T01:20:00Z</dc:date>
    <item>
      <title>Real time threat detection</title>
      <link>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453136#M99270</link>
      <description>&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make real time detection more effective, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to find the Cisco device alert pattern for real time detection of attack? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, SQL slammer worm, Cisco IDS will fire its related/specific signature. For any Trojan activity IDS will fire specific signature. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how to find a signature patter, or packet pattern for session hijack, ip spoofing and other IP based attacks? (not related to applications) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any knowledge source, which can show traffic/packet pattern generated by IP based attacks/protocol behavior in attack? What kind of alerts for what kind of attack, sequence of alerts, etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using netForensics for real time threat detection; I want to make some rules which will match the IP behavior/IDS signature generation pattern in progressing attack. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for such kind of knowledge base, if any one have experience in this please help me out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;Kapish &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453136#M99270</guid>
      <dc:creator>kapishmohole.cisco</dc:creator>
      <dc:date>2019-03-10T09:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Real time threat detection</title>
      <link>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453137#M99272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kapish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at cs-mars. &lt;A class="jive-link-custom" href="http://www.cisco.com/go/mars." target="_blank"&gt;www.cisco.com/go/mars.&lt;/A&gt; This is an awesome reporting, analysis and mitigation system. I've been involved in Cisco security product for nine years and this is the most comprehensive security reporting and analysis system I've seen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2005 17:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453137#M99272</guid>
      <dc:creator>gabelar</dc:creator>
      <dc:date>2005-06-10T17:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Real time threat detection</title>
      <link>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453138#M99274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, that was a cool link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it didnt show any information on attack progress, stages of attack and alert pattern that normal Cisco IDS will generate for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for deep analytical information, which will show me how to correlate alerts manually. I am using netForensics, I want to make rules in it for IDS and PIX using my understanding to find attack at its point of progress.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Kapish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Jun 2005 01:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/453138#M99274</guid>
      <dc:creator>kapishmohole.cisco</dc:creator>
      <dc:date>2005-06-11T01:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Real time threat detection</title>
      <link>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/3762529#M99276</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.nwexam.com/cisco/cisco-600-199-certification-exam-syllabus" target="_blank"&gt;&lt;STRONG&gt;Threat protection&lt;/STRONG&gt;&lt;/A&gt; is comprised of the Sourcefire® SNORT® intrusion detection engine and AMP anti-malware technology.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 04:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/real-time-threat-detection/m-p/3762529#M99276</guid>
      <dc:creator>nikki_carol</dc:creator>
      <dc:date>2018-12-27T04:29:36Z</dc:date>
    </item>
  </channel>
</rss>

