|
|||||||||||
|
H/N IPS -what is there?
From: Talisker <talisker(at)networkintrusion.co.uk>
Date: Wed Dec 11 2002 - 17:09:31 EST
Hi
It's that time when I need to seriously look at updating the site.
http://www.networkintrusion.co.uk Firstly the definitions; by Corporate I mean that they can be managed remotely and they will report into a central console ie not just the local host. Intrusion Prevention System (IPS). More proactive than the traditional IDS, they actively block traffic deemed as malicious, almost like a firewall but using IDS techniques to block an attack.
Host IPS. A HIPS will block an attack aimed at the Host upon which it is
situated, previous names for a HIPS have included Network Node IDS (NNIDS)
or personal firewall. To quote nss
Network IPS. What used to be called an inline IDS, it's an IDS with 2 interfaces, it will block those packets that trigger the criteria laid down by the IDS. examples TippingPoint UnityOne and RealSecure Guard I'm hoping to get the pages up with a general overhaul over Christmas, my real job is keeping me too busy these days, so many incidents, so little time! I'm looking for a good starting place and therefore looking for lists containing HIPS and NIPS to start me off on the research, in return I will collate all the information and feed a summary back into the list. Bibliography: NSS http://www.nss.co.uk who have just published a review on gigabit IDS
take care, and cheers for any time you can spare
-andy
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT |
||||||||||
|
|||||||||||