4 ms·
For me I see IDS as a natural easy win; collating a shitload of sensor data, tripwires, logs... and providing carefully graded alerts and advice seems like some
by nonrandomstring 3y ago
For me I see IDS as a natural easy win; collating a shitload of sensor
data, tripwires, logs... and providing carefully graded alerts and
advice seems like something ANN trained on lots of good field data
would excel at.
- potatohead00 3y agowhere will this good field data come from? using what context? a low risk alert for one org might be seen as something else in another.
- asynchronous 3y agoIf you look at the current major offerings like SentinelOne, they start off with a generic best practice baseline, then slowly “learn” the normal traffic on the network to be able to better define the abnormal incidents to the IDS.
- nonrandomstring 3y agoYou make a good point. What occurred to me is that some more standardised method for coding threat events is needed first. But that seems tractable given existing CVE taxonomies etc.