Detecting phising scams on wire



I am working on IPS signatures to detect phising scams on wire.
the points in my mind are
IPS should have capabilty to validate the IP addresses using reverselookup or by maintaining a list of blacklisted IPs.
to check SSL validation for commercial sites on wire to prevents url spoofing
i would appreciate your comments and suggestion

thanks in advance



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: Detecting phising scams on wire
    ... > I am working on IPS signatures to detect phising scams on wire. ... > IPS should have capabilty to validate the IP addresses using ... for the personal web-mail (since that doesn't traverse a corporate MTA), ...
    (Focus-IDS)
  • RE: newbie quetsions
    ... I would have to concur with you about the ability to push packets down the ... I'm not quite sure, however, why you're bashing the NSS IPS tests. ... such as pushing packets down a wire." ...
    (Focus-IDS)
  • RE: Detecting phising scams on wire
    ... reverse lookup is not the only dead giveaway that ... different URL at a different domaincontained in the message body. ... Bayesian CPU scratching you want to do in real-time with your IPS is up to ... silver bullet that reliably kills phishing on the wire. ...
    (Focus-IDS)
  • Re: KSSL only not negotiate protocol
    ... Have the user type the password over the wire ... > (using SSL-protected communication), then validate the password using ...
    (comp.protocols.kerberos)