RE: Denial of Service: Commercial Defense products

From: Joel Friedman (jfriedman_at_datapipe.com)
Date: 11/23/05

  • Next message: Talisker: "RE: Denial of Service: Commercial Defense products"
    Date: Wed, 23 Nov 2005 15:07:13 -0500
    To: <focus-ids@securityfocus.com>
    
    
    

    Riverhead (now Cisco Guard) is by far the best choice. We had a little in
    house shoot-out where we attacked multiple vendors' hardware and graphed
    their results into the millions of packets per second. Due to NDA's we are
    not allowed to disclose which vendors, nor their results, but I can say that
    Riverhead successfully defended against more than twice the load of its
    competitors...at the time it was able to stop approximately 1.5 million SYN
    packets per second while still allowing legitimate traffic.

    IMHO there is no other choice.

    --Joel

    -----Original Message-----
    From: Kyle Quest [mailto:Kyle.Quest@networkengines.com]
    Sent: Wednesday, November 23, 2005 2:42 PM
    To: focus-ids@securityfocus.com
    Subject: RE: Denial of Service: Commercial Defense products

    You should really look at Top Layer if you are serious
    about defending against denial of service attacks.
    Don't even waste your time on Mazu or McAfee.
    Tipping Point is suppose to get better at it
    as well (they were working on some news things
    the last time I had a chance to talk to one
    of their top guys), but I don't know if it's
    already available.

    I would recommend looking at the NSS reports
    (http://www.nss.co.uk/download/download.htm).
    Unfortunately, the online version of the report
    that includes Top Layer review is no longer available,
    but you can still buy it for a couple of bucks.

    Kyle

    -----Original Message-----
    From: Ogle [mailto:myinfosec@gmail.com]
    Sent: Tuesday, November 22, 2005 4:44 AM
    To: focus-ids@securityfocus.com
    Subject: Denial of Service: Commercial Defense products

    Hi,
    I have an ISP customer who want to protect their network and their
    subscriber's network.
    In "Internet Denial of Service: Attack and Defense Mecahnisms" book, I
    noticed 7 commercial products.
    1. Mazu Enforcer by Mazu Networks
    2. Peakflow by Arbor Networks
    3. WS Series Apliances by Webscreen Technologies
    4. Captus IPS by Captus Networks
    5. MANAnet Shield by CS3
    6. Cisco Traffic Anomaly Detector XT and Cisco Guard XT
    7. StealthWatch by Lancope

    Since I'm new with this type of products, is there any reference out
    there to help me choose the right solution to my customer ?
    Is there any problem if I use IPS (ie: TippingPoint, McAfee) for this
    solution ?

    Thanks.

    
    



  • Next message: Talisker: "RE: Denial of Service: Commercial Defense products"

    Relevant Pages

    • Re: Hackers Attack Via Chinese Web Sites
      ... > U.S. Agencies' Networks Are Among Targets ... > Defense Department and other U.S. agencies, ... > Classified systems have not been compromised, the officials added. ... > simply using Chinese networks to disguise the origins of the attacks. ...
      (soc.culture.african.american)
    • Hackers Attack Via Chinese Web Sites
      ... Hackers Attack Via Chinese Web Sites ... U.S. Agencies' Networks Are Among Targets ... Web sites in China are being used heavily to target computer networks in the ... Whether the attacks constitute a coordinated Chinese government campaign to ...
      (soc.culture.african.american)
    • Instant-Messaging Attacks Increase in 2005
      ... Security attacks over instant-messaging networks became more prevalent ... Monday by IM security vendor FaceTime Communications. ... But in 2005 there were more crossovers from AOL to the MSN ...
      (comp.dcom.telecom)
    • [Full-disclosure] Hacking Exposed Cisco Networks
      ... In the meantime you can download a sample chapter, get additional info about the book and download related tools from the book's official web page. ... Defend against the sneakiest attacks by looking at your Cisco network and devices through the eyes of the intruder. ... Hacking Exposed Cisco Networks shows you, step-by-step, how hackers target exposed systems, gain access, and pilfer compromised networks. ...
      (Full-Disclosure)
    • RE: Denial of Service: Commercial Defense products
      ... Cisco Guard doesn't actually 'stop' SYN packets - it ... tells routers where the bad traffic is coming from, ... Our ISP uses Cisco Guard, but we tell them to turn it ... Mazu Enforcer by Mazu Networks ...
      (Focus-IDS)