Re: Gateway IDS

From: Shaiful (shaifuljahari@yahoo.com)
Date: 06/25/02


Date: Mon, 24 Jun 2002 22:28:16 -0700 (PDT)
From: Shaiful <shaifuljahari@yahoo.com>
To: Jochen Vogel <jvogel@it-sec.de>

Hi,

Have you looked into hogwash based solution? There are
currently two primary versions, libpcap/libnet and
iptables/libipq approach. IMHO, the hogwash approach
is much better than sending RESET packet since an
attacker can always modify his IP stack to ignore the
RST packet. Pls see following links:

Original hogwash using libpcap/libnet:
http://hogwash.sourceforge.net/

Experimental iptables/libipq approach:
http://www.prismnet.com/~aef/index2.html

IDS gateway for honeypot(using iptables/libipq):
http://w3.cablespeed.com/~rvmcmil/IDSGateway/idgateway.htm

Best regards,
Shaiful

--- Jochen Vogel <jvogel@it-sec.de> wrote:
> hi,
>
> since last year i search a working gateway IDS
> solution.
> i search a solution that work like a firewall but
> additionally
> can block packets after an correlation with IDS
> signatures.
> the solution to send RST packets or reconfigure a
> firewall
> is nice but not really about latency or spoofing
> packets.
>
> greets
> Jochen
>

__________________________________________________
Do You Yahoo!?
Yahoo! - Official partner of 2002 FIFA World Cup
http://fifaworldcup.yahoo.com



Relevant Pages

  • Re: iptables anti-nimda anyone?
    ... Subject: iptables anti-nimda anyone? ... >> filling up my apache logz and would love to drop the packets 'ere they ... Something worth looking into would be hogwash, it is a packet scrubber based on snort. ... closing ports like a traditional firewall, ...
    (Focus-Linux)
  • Re: [fw-wiz] GIDS, Intrusion Prevention: A Firewall by Any Other Name
    ... > you probably realized by now that you meant Hogwash, ... Aw crap. ... > don't think it 'normalizes' packets in terms of reshaping them and ... Here's the link I should have looked up before calling it Barnyard: ...
    (Firewall-Wizards)