IDS #243

Closed
thestinger opened this Issue Apr 22, 2016 · 3 comments

Comments

Projects
None yet
2 participants
@thestinger
Contributor

thestinger commented Apr 22, 2016

It would be cool to have optional built-in IDS support. It's not possible to do this well without it being built into the OS due to lack of privileges, especially as the app sandbox is hardened. It's an area where CopperheadOS could provide a real edge. Android has SafetyNet, but that's meant to protect the ecosystem as a whole, not individuals.

@xmikos

This comment has been minimized.

Show comment Hide comment
@xmikos

xmikos Apr 25, 2016

It would be great if it could also detect QUANTUM INSERT attacks, see here: Deep dive into QUANTUM INSERT (configuration for Bro, Snort and Suricata IDS here: https://github.com/fox-it/quantuminsert/tree/master/detection).

Not only NSA, but now even Chinese, Malaysian and Indian malware and ad networks seems to be doing QUANTUMINSERT-style man-on-the-side attacks: Website-Targeted False Content Injection by Network Operators

xmikos commented Apr 25, 2016

It would be great if it could also detect QUANTUM INSERT attacks, see here: Deep dive into QUANTUM INSERT (configuration for Bro, Snort and Suricata IDS here: https://github.com/fox-it/quantuminsert/tree/master/detection).

Not only NSA, but now even Chinese, Malaysian and Indian malware and ad networks seems to be doing QUANTUMINSERT-style man-on-the-side attacks: Website-Targeted False Content Injection by Network Operators

@thestinger

This comment has been minimized.

Show comment Hide comment
@thestinger

thestinger Feb 10, 2017

Contributor

Not planned.

Contributor

thestinger commented Feb 10, 2017

Not planned.

@thestinger thestinger closed this Feb 10, 2017

@thestinger

This comment has been minimized.

Show comment Hide comment
@thestinger

thestinger Apr 25, 2018

Contributor

This is going to be revived as part of our Auditor app: copperhead/Auditor#27.

Contributor

thestinger commented Apr 25, 2018

This is going to be revived as part of our Auditor app: copperhead/Auditor#27.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment