re[2]: Gateway IDS

From: Christopher Cantrell (cantrell@onesecure.com)
Date: 06/26/02


Date: Wed, 26 Jun 2002 11:24:43 -0600
From: Christopher Cantrell <cantrell@onesecure.com>
To: <r00t@online.ie>, Jochen Vogel <jvogel@it-sec.de>

Hi,

Just a note to add:

>> You my have already checked it out but:

>> ISS RealSecure works quite well with Checkpoint Firewall 1, there are
>> actionable options available per signature including the ability to send
>> RST's
>> to attacker hosts.

Most IDS products can integrate with other devices (i.e. CheckPoint OPSEC), but IP blocking can be a very risky "reaction". A better approach, is to look at a product which can maintain state on all sessions (not just TCP) and be able to "drop" those session which offend a security policy. By maintaining state, you achieve a lot of benefits including the ability to only "drop" the session which has an attack and not any other sessions, even if they are all coming from a single NAT'ed IP address.

Best regards,
-chris



Relevant Pages

  • Re: MOTHERBOARD INFO
    ... Regards ... > Windows does not provide any utility to do this directly. ... >> or leave signature otherwise posts will ...
    (microsoft.public.windowsxp.help_and_support)
  • Isnt that Special!
    ... >> Bush's signature, (like his word re media leaks and susequent job ... >> Regards, ... >> Tim O ...
    (sci.energy)
  • Re: Multiple SMTP Domains and sending Account choices
    ... > Best Regards, ... >> I know that you can set up the ability to receive mail from two domains ... >> one exchange server. ... My question is in regard to sending mail. ...
    (microsoft.public.windows.server.sbs)
  • Re: Oversized Sigs/Rudimentary Web Design
    ... >> Best regards, ... > signature, i.e. below the sigdash. ... >> Don Kelloway, Commodon Communications ...
    (comp.security.misc)
  • Re: Oversized Sigs/Rudimentary Web Design
    ... >> Best regards, ... > signature, i.e. below the sigdash. ... >> Don Kelloway, Commodon Communications ...
    (alt.computer.security)

Loading