|
|||||||||||
|
Re: IDS and forensics
From: Talisker <offthecuff(at)lineone.net>
Date: Mon Jan 27 2003 - 13:37:50 EST
Hi Carv
Snort and SecureNetPro will catch the offending packets, though both can easily catch all packets if set to do so. With SecureNetPro you can install TCPdump, or you set logging for certain events to include packet dump. This is on a event by event basis, so it can be time consuming getting the settings correct. (I could be wrong) BlackICE is very cool not only does it retain the offending packet in an evidence file but is also has a sliding window where it catches all packets, overwriting the older ones in accordance with your settings. On a busy network though you have to get in there quick or have a HUGE drive. BlackICE has been end of lifed by ISS replaced by RealSecure, I'm doing their advanced course in a few weeks so I can get back to you on how well it does packet capture, though I'd be very surprised if any IDS out there didn't at least log offending packets. For reactive forensics ie you know something is going on and you want to catch them in the act then SecureNetPro through it's Linux console will allow you to watch live sessions as they materialise great for Hotmail etc. Through it's new Windows client is has a pretty cool forensics interface. This to me isn't what I call forensics but it does allow you to get to the bottom of a problem on a big network. At the end of the day though you can't beat (IMHO) Ethereal it has fantastic network protocol savvy, though Iris has a nice front end and allows you to replay the packets without having to feed them through TCP Replay, say on a test network.
Take care
Taliskers Network Security Tools
> I'm interested in other's views of network IDS systems
This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Mon Jan 27 15:25:00 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:43 EDT |
||||||||||
|
|||||||||||