looking for wireless IDS whitepaper

From: Evans, Arian (Arian.Evans_at_fishnetsecurity.com)
Date: 08/26/05

  • Next message: Rivera,Angel L.: "RE: using HIDS for change control"
    Date: Fri, 26 Aug 2005 11:48:48 -0500
    To: <focus-ids@lists.securityfocus.com>
    
    

    I recently (<=2 months) read a wireless IDS
    whitepaper discussing four + wireless IDS/IPS
    vendors and the utility of their "security"
    mechanisms. Alas, I cannot find this pdf anywhere.

    It covered things like dropping disassociation
    packets by changing the linux ip stack to ignore
    the disassociation bit, etc.

    Nice short read, very politically correct regarding
    the various vendors implementing dubious controls.
    Had a little chart of what vendors implement what
    control/defense mechanisms.

    Anyone know what paper I am speaking of and have
    a link to it? Feel free to be a smartass and send
    me the correct Google query. Many thanks,

    -ae

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Rivera,Angel L.: "RE: using HIDS for change control"

    Relevant Pages

    • RE: Recent Gartner IDS/IPS report
      ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
      (Focus-IDS)
    • Re: On IDS Evasion, Vulnerabilities, and Vendor Hype
      ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... encoding, unlike %u encoding." ... How long was it before some vendors ... > vulnerability. ...
      (Focus-IDS)
    • On IDS Evasion, Vulnerabilities, and Vendor Hype
      ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... IDS vendors sometimes must completely rewrite parts of their engines ... Eeye cast the first stone with their advisory %u encoding IDS bypass ... vulnerability. ...
      (Focus-IDS)
    • On IDS Evasion, Vulnerabilities, and Vendor Hype
      ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... IDS vendors sometimes must completely rewrite parts of their engines ... Eeye cast the first stone with their advisory %u encoding IDS bypass ... vulnerability. ...
      (Bugtraq)
    • RE: Intrusion Prevention
      ... but the same is true for all commecrcial vendors ... >sometimes we're told that we cannot see the testing methodology upfront. ... >This dumbfounds me for all the reasons that MJR already ... IDS testing is too easy to inadvertently (and sometimes ...
      (Focus-IDS)