Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Active response... some thoughts.

From: Rob McMillen <rvmcmil(at)cablespeed.com>
Date: Wed Feb 05 2003 - 18:10:23 EST


On Mon, 3 Feb 2003, Gonzalez, Albert wrote:

> Blocking isn't just sending TCP rst's or the various other methods. Some

snort-inline does not add rules to the firewall. It is linked to the ipqueue facility which sends packets from kernel space to userspace where a program (snort-inline) can make a drop or accept decision. snort-inline makes this decision based on the drop rules.

> SnortSam and Snort-inline can both talk to IPtables, iptables can just

In the next release of snort-inline, it will be able to reject connections with tcp resets for tcp connections and icmp unreach for udp.

Also, combined with the Honeynet Project's rc.firewall script, snort-inline can operate with iptables at layer2 (bridging firewall). This means the device can be dropped in front of your existing system without having to change ip addressing. Also, since it is a layer 2 device, it is invisible to the bad guy (unless you put an ip on it).

Hope this helps,

Rob Received on Thu Feb 6 11:57:04 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:09 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library