RE: Active response... some thoughts.
On Mon, 2003-01-27 at 19:26, Kohlenberg, Toby wrote:
> Actually, TCP resets don't work in many cases- for instance any
In regards to firewall/router reconfig:
Yeah, the damage is done and reconfiguring firewalls don't help
'prevent' that attack, but they can help 'contain' that attack. For
example, the firewall can be reconfigured to deny any traffic to and
from that attacked device. While in this worm scenario it only prevents
the infected host from flooding the Internet, and perhaps internal
network, it doesn't prevent other infected hosts on the local segment
from flooding out (unless your IDS/firewall tandem is configured in a
smart way1), it does work very well on normal backdoor and bo attacks.
Even in this scenario the host gets compromised, but the connection to
the attacker is then cut off by the firewall and the rooted system is
contained through firewall rules.
Regards,
Frank
[1] Smart way could be denying all packets of the same service crossing
the firewall. That would prevent other, locally infected, hosts from
flooding out.
Received on Wed Jan 29 12:21:58 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:07 EDT
|