Click here to Skip to main content
15,889,216 members
Please Sign up or sign in to vote.
0.00/5 (No votes)
Hi
where can i get virus signatures and attack signatures for a network intrusion detection system.
Posted

I don't think there's a free public database available. There were attempts to start a free and open source virus signature DB but they all got abandoned. It's a very expensive task to keep it updated since new viruses and trojans are detected on a daily basis (sometimes multiple times daily).
 
Share this answer
 
v2
Comments
ashborg 28-Oct-10 19:29pm    
and for recognizing DOS Attacks on a network?
Nish Nishant 28-Oct-10 19:31pm    
Well that's different from signatures. Most DOS attacks are detected by monitoring for unusual port connection activity on your public IP addresses.

Some use buffer overflows to root a system or to DOS it. Again, while there are tons of sites that post new vulnerabilities and shell-code on a daily basis, there is no single point public source that's comprehensive and updated regularly.
By decompiling/disassembling viruses.
 
Share this answer
 
Comments
ashborg 28-Oct-10 19:29pm    
how do i do that?
LloydA111 28-Oct-10 19:33pm    
That is like asking how to build a space rocket. It's very complicated and the sort of people that do it regulary tend to not divulge too much information (Anti-virus companies definitely don't tell people). Have a look around on the internet for it, it comes up with some seriously in-depth ideas and code.

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900