RE: Top IPS vendors - please read for invitation to Network World review.

From: Evans, Arian (Arian.Evans_at_fishnetsecurity.com)
Date: 08/28/03

  • Next message: Frank Knobbe: "Re: Network IDS"
    Date: Thu, 28 Aug 2003 08:55:52 -0500
    To: "dodo" <ro_dodo@hotmail.com>, "Andrew Plato" <aplato@anitian.com>, <talisker@networkintrusion.co.uk>
    
    

    et al,

    > You forgot the one of the newest: www.forescout.com

    I wouldn't call their product Host IPS, if you are responding to
    the request below.

    It's definitely a network product; not sure IPS is right; it's more
    about blocking traffic based upon identification of recon, sending
    fake responses, etc. It's something you'd throw out on your
    extended edge and help cut down on what gets past that....
    e.g.-reduce firewall and IDS traffic/logs. Has pretty reports.

    Not sure where I'd really put it. It's definitely a step above
    TCP-reset technology but it sure won't scrub directed attack
    traffic so IPS doesn't seem to fit.

    Pentasafe/now/NetIQ VSAWS is Host IPS. Part tripwire part
    HTTP traffic sanitization.

    Cheers,

    Arian Evans
    Sr. Security Engineer
    FishNet Security

    Phone: 816.421.6611
    Toll Free: 888.732.9406
    Fax: 816.421.6677

    http://www.fishnetsecurity.com

    note: Microsoft Office XP breaks text-based
    email by default.

    Turn off the "remove extra line breaks" located
    at |Tools|Options|Email Options if this formats
    incorrectly.
    #
    #----- Original Message -----
    #From: "Andrew Plato" <aplato@anitian.com>
    #To: <focus-ids@securityfocus.com>
    #Cc: <talisker@networkintrusion.co.uk>
    #Sent: Wednesday, August 27, 2003 3:41 AM
    #Subject: Re: Top IPS vendors - please read for invitation to
    #Network World
    #review.
    #
    #
    #>What I am very interested in would be a good list of Host Intrusion
    #>Prevention Systems - it's something I've been meaning to tackle for
    #some
    #>time for inclusion on the site, some are on my Host IDS page
    #.......I've
    #>been concentrating on providing salient details on security training
    #courses
    #>recently sadly letting IDS and scanners slip.
    #

    The information transmitted in this e-mail is intended only for the addressee and may contain confidential and/or privileged material.
    Any interception, review, retransmission, dissemination, or other use of, or taking of any action upon this information by persons or entities
    other than the intended recipient is prohibited by law and may subject them to criminal or civil liability. If you received this communication
    in error, please contact us immediately at 816.421.6611, and delete the communication from any computer or network system.

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training), October 1-2 (Briefings) in Tysons Corner, VA; the world’s premier
    technical IT security event. Modeled after the famous Black Hat event in
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    Symanetc is the Diamond sponsor. Early-bird registration ends September 6 Visit: www.blackhat.com
    ---------------------------------------------------------------------------


  • Next message: Frank Knobbe: "Re: Network IDS"

    Relevant Pages

    • Re: IDS vs. IPS deployment feedback
      ... an enterprise network and its security? ... I manage information security for an organization of 3500 employees;-). ... You have to size your IPS accordingly. ... enterprise networks are complex and have limited resources to handle ...
      (Focus-IDS)
    • RE : Experiences with Toplayer Attack Mitigator IPS
      ... Objet: Re: Experiences with Toplayer Attack Mitigator IPS ... I'm still waiting for the report from the network ... security vendors are so fond of touting nowadays? ...
      (Focus-IDS)
    • RE: Experiences with Toplayer Attack Mitigator IPS
      ... Experiences with Toplayer Attack Mitigator IPS ... network intrusion uk guys who are coming out with the IPS shootout ... as security vendors are so fond of touting nowadays? ... > - Make firewall, VPN, and NAT rules interoperable across heterogeneous ...
      (Focus-IDS)
    • RE: Experiences with Toplayer Attack Mitigator IPS
      ... Most of the security vendor now going for all in one. ... For Small to medium network, ... > network infrastructure, layer 7 switches, firewalls, routers, etc. ... made the call and started the process of obtaining an IPS ...
      (Focus-IDS)
    • RE: RE : Experiences with Toplayer Attack Mitigator IPS
      ... It will include reviews of the main players in the Network IPS market ... would like to be in Edition 2 of the report (or IDS vendors who wish to ... >> install a new security device after investing in 1 FW, IDS, ...
      (Focus-IDS)