Port and File-Blocking Best Practices

From: Dave (anonymous_at_discussions.microsoft.com)
Date: 03/04/05


Date: Thu, 3 Mar 2005 16:50:46 -0800

Hi All,

Does there exist anywhere a list of port- and file-blocking
"best practices" for use with intrusion
detection/prevention apps running on Windows 2000?

I recently purchased McAfee VirusScan Enterprise and am
very pleased with the ease by which I can block ports to
all but trusted/specified apps and also block or log access
to sensitive files and directories. I imagine that other
apps are similarly convenient to setup and use (compared to
the obnoxiously cryptic Event Viewer auditing).

But the sample rules have only whetted my appetite. For
example, changes to various filetypes are logged, including
EXE, DLL, PIF and SCR. Likewise, web downloads (port 80)
are restricted to all but iexplore.exe, etc. I know there
are plenty of other file extensions and rules to use with
such apps.

Does a list of "best practices" exist?

Any advice is appreciated.



Relevant Pages

  • RE: Port and File-Blocking Best Practices
    ... apps / ports, etc. and seek management support and approval to roll it out. ... > to sensitive files and directories. ... > But the sample rules have only whetted my appetite. ...
    (microsoft.public.win2000.security)
  • Re: Best Codeplex sample for showing best coding practices?
    ... joint creations and apps, not for illustrations of "Best practices". ... However, there is an entire section on best practices on MSDN online, ... You can also download and look at the ...
    (microsoft.public.dotnet.framework.aspnet)
  • Best Practices GUI Design Whitepaper
    ... A very nice paper on prevalent GUI design best practices for C/C++ apps ...
    (comp.lang.cpp)
  • References to ISA
    ... I need some good references to using ISA with ASP.Net apps created in Visual ... Studio. ... Does anyone know of some good whitepapers, best practices, etc? ...
    (microsoft.public.dotnet.framework.aspnet.security)

Quantcast