Re: IDS vs Application Proxy Firewall



an application proxy firewall normally looks for packets that do not
behave like how they are supposed to be as defined by the protocol
standards (RFC)..while an IDS looks for signs of an active attack in a
perfectly legitimate packet that is crafted according to standards..of
course..misbehaving packets are normally picked out by an IDS as well.
hope this helps!

2008/10/22 <maash.rajani@xxxxxxxxx>

Can someone please explain how is an IDS different from an application proxy firewall in terms of what each of them looks for in a packet.

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------




--
./Zhihao

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------