[46] in Intrusion Detection Systems
FYI -- Network Intrusion Detector (NID)
daemon@ATHENA.MIT.EDU (James O. (Jim) Truitt)
Mon Apr 3 06:29:04 1995
Date: Sat, 01 Apr 1995 17:28:13 -0500
To: ids@uow.edu.au
From: jtruitt@iu.net (James O. (Jim) Truitt)
Reply-To: ids@uow.edu.au
Try URL: http://ciac.llnl.gov/cstc/CSTCProducts.html
Network Intrusion Detector (NID)
Description
The Network Intrusion Detector (NID) software product provides a suite of
security tools that
detects and analyzes network intrusions. NID provides detection and analysis
of intrusions from
individuals not authorized to use a particular computer, and from
individuals allowed to use a
particular computer but who perform either unauthorized activities or
activities of a suspicious nature
on it.
NID provides effective and inexpensive network intrusion detection capability:
Hosted on a single, network-connected Unix workstation (Sun Sparc,
SunOS 4.1.x).
Combines three detection techniques:
Attack signature recognition (most effective).
Anomaly detection.
Vulnerability risk model.
Typically used in retrospective mode; a real-time, alarm-like
capability being developed.