|
|||||||||||
|
Re: slow scans?
From: Anton Chuvakin <anton(at)chuvakin.org>
Date: Wed Feb 12 2003 - 16:38:01 EST
Thanks for the response. >It really depends on what you want to know.
>For example, if you want to detect someone trying to do slow
>"I've seen a RST packet leave from a high port on 100+ machines
>To my knowledge, Dragon and NFR do look for these sorts of
>Also, protocol-flow anomaly detection tools like
>Personally, the advantage is on the attacker, as they can
>one of the things we did in Dragon was to look for 'hot ports'.
>tell with much greater accuracy what has occurred than a
Best,
--
Anton A. Chuvakin, Ph.D., GCIA
http://www.chuvakin.org
http://www.info-secure.org
Received on Wed Feb 12 16:50:49 2003This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:10 EDT |
||||||||||
|
|||||||||||