Re: TippingPoint vs. Intrushield

Justin.Ross_at_signalsolutionsinc.com
Date: 07/15/04

  • Next message: Gustavo Rodrigues Ramos: "[off-topic] Port mirroring"
    To: focus-ids@securityfocus.com
    Date: Thu, 15 Jul 2004 11:39:15 -0700
    
    

    Jacob:

    I implemented a TippingPoint for my prior employer (Govt. service
    provider). It performed extremely well blocking 400,000+ attacks per day
    (mostly Nimda, etc.). It was transparent to our clients (except where they

    saw the drop off of worm attacks), and allowed us to get extremely
    granular in what we wanted to "recognize" and alert/ block on using their
    "custom shield writer".

    We also used it to enforce policy (such as disallowing Kazaa regardless of
    port number used, etc.) It was easy to
    configure and manage. I personally would recommend it to anyone looking
    for an IPS product.

    Just my $0.02

    Justin Ross
    MCP+I, MCSE, CCNA, CCSA, CCSE, CCSI
    Senior Network Security Engineer
    Signal Solutions Inc. - http://www.signalcorp.com
    101 Wilcox Dr.
    Sierra Vista, AZ 85635
    Phone: (520) 459-1354 x3095
    Cell: (520) 234-4080
    Fax: (520) 459-1428
    Email: Justin.Ross@signalsolutionsinc.com

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from CORE
    IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
    --------------------------------------------------------------------------


  • Next message: Gustavo Rodrigues Ramos: "[off-topic] Port mirroring"

    Relevant Pages

    • Re: How do I share files (securely) using wifi modem/router?
      ... and printer sharing be concerned about (from the link above, using SPI): ... blocking Java, ActiveX, and Cookie portions of downloaded web pages ... blocking "IP Spoofing" attacks ... My router with NAT blocks SYN flood attacks, ...
      (alt.internet.wireless)
    • Re: How do I share files (securely) using wifi modem/router?
      ... and printer sharing be concerned about (from the link above, using SPI): ... blocking Java, ActiveX, and Cookie portions of downloaded web pages ... blocking "IP Spoofing" attacks ... John Navas FAQ for Wi-Fi: ...
      (alt.internet.wireless)
    • Re: Firewall Setup...
      ... blocking svchost.exe stops your machine from accessing ... >> Internet. ... So without knowing what DCE is, maybe they are not 'attacks' ...
      (comp.security.firewalls)
    • LSASS_RPC_DS_Request
      ... I'm a home office PC user, with Windows XP. ... my firewall keeps blocking "High ... Level" attacks from a MS address: ...
      (microsoft.public.windowsxp.security_admin)
    • RE: Publishing Nimda Logs
      ... automated attacks and noise on the networks. ... From an incident response standpoint, the load is very demanding as the ... number of systems actively performing NIMDA scans grows/continues. ...
      (Incidents)

  • Quantcast