Re: ISS - virtual patching



I don't get it. How do signatures get their status (detection only or also prevention)?
Do the vendors release the signatures with this marked in the signature or does the SOC team need to read the signatures and decide one by one how to deploy them for each device?

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • RE: Signatures taking down network
    ... This is a nightmare scenario for any IPS ... signatures I'm having problems with the box "crashing". ... Is there a trend with vendors to roll out signatures as fast as ... I want proper QA so that it ...
    (Focus-IDS)
  • RE: Signatures taking down network
    ... I can tell you that it is very challenging for the vendors to produce ... produce protection signatures as quickly as possible so as not to leave ... So, if you will produce a quality signature, you must ... ISS is also a managed services provider for a large number of customers. ...
    (Focus-IDS)
  • Re: Obfuscated shellcode
    ... Sounds like a reason not to use these "major vendors". ... vendors write signatures that are so easy to avoid and a number of them ... As for obfuscated NOOP's and shell code, ...
    (Vuln-Dev)
  • RE: IDS vs. IPS deployment feedback
    ... I cannot speak for other vendors, but I suspect that many of the vendors ... ISS, like every vendor, have certain QA processes that they go through ... ISS also has anomaly based signatures. ... You ask how many false negatives can get through a default IPS ...
    (Focus-IDS)
  • Re: Vulnerability & Exploit Signatures
    ... > I doubt there is any licensing of base signatures between vendors ... own signatures based on someone else's research. ... >> CORE IMPACT. ...
    (Focus-IDS)