|
|||||||||||
|
Re: Active response... some thoughts.
From: Talisker <talisker(at)networkintrusion.co.uk>
Date: Mon Jan 27 2003 - 14:10:06 EST
Hi Toby (LTNS)
Another problem with crafted resets through the stealth interface is being
able to convince the security accreditors that your IDS is not bypassing the
firewall.
Going back to the original post I think Ron's solution (as always) holds a lot of merit and is used by at least one other vendor. Though Marty's solution of sending back at the TTL of the offending packet is cool, though I would add a few. I'm sure SecureNetPro crafts and sends the resets both ways through the stealth interface.
take care
Taliskers Network Security Tools
I looked at the whole active response thing a while ago and have yet to see anything that changes my basic opinionvery few events are well defined enough to trust an automated response that could cause problems for a customer. The coolest response I've seen was from Dragon which can send false/funky responses to an attacker when it sees a scan going on. It will be a long time before I think IDSs will be trustworth enough to use such technology frequently. (all opinions are my own and in no way reflect the views of my employer) toby > -----Original Message-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:06 EDT |
||||||||||
|
|||||||||||