Re: IM Programs

From: Johannes B. Ullrich (jullrich@sans.org)
Date: 03/13/02


Date: Tue, 12 Mar 2002 19:38:03 -0500 (EST)
From: "Johannes B. Ullrich" <jullrich@sans.org>
To: c_brauckmiller@LEK.COM


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> It is virtually impossible to block them with a firewall.

Maybe a firewall is the wrong way. How about using an IDS?
The basic idea:

- - Define and publish a company wide policy outlawing the use
  of Instant Messengers.
- - Use an IDS to monitor if the policy if violated.

The other problem you are having is users installing software.
Something that has to be eliminated if you try to run a
secure network.

- --
- -------
jullrich@sans.org Join http://www.DShield.org
                          Distributed Intrusion Detection System

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8jp9twWQP+4im9DYRAuDmAJ9OxsNEcPxhFz/9JHqnuYycBswtXgCePWax
V/cQWxnRCGalv/w8koQ7+48=
=+IpE
-----END PGP SIGNATURE-----



Relevant Pages

  • RE: [Full-Disclosure] logically stopping xss
    ... Hash: SHA1 ... but I was wondering if there is any firewall or IDS ... Not just GET requests should be checked. ...
    (Full-Disclosure)
  • RE: Thinking about Security rules...
    ... > Subject: Re: Thinking about Security rules... ... >>rules for the IDS. ... by which you attack. ... firewalls in series isn't nearly as nice as a stateful firewall coupled ...
    (Vuln-Dev)
  • Re: Is IDS/IPS worthless?
    ... >>firewall instead of in front of it should BOTH ... >>fill in the gap left by the false sense of security firewalls give (a ... >IDS technology and I certainly believe in the usefullness of IDS. ... that is confusing IDS and NIDS together. ...
    (Focus-IDS)
  • Gartner comments (was Re: Rather funny; looks like page defacement to me)
    ... All IDS systems produce falses. ... In fact, all network security ... firewall monitoring long before they deployed their first IDS. ... Gartner, you really missed the boat on this one. ...
    (Focus-IDS)
  • Re: IDS on Switched Networks
    ... connecting a network IDS to it would be fine. ... Higher state of alert you know what attacks you are ... If your firewall has NAT turned on, ...
    (Focus-IDS)