Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




focus-ids logo IDS mailing list archives

Re: Intrusion Prevention
From: Vern Paxson <vern () icir org>
Date: Mon, 09 Dec 2002 23:13:13 -0800

FYI, the way it works is by responding to scans with bogus replies that are
unique to a particular scan.  Then, when subsequent attack traffic includes
the fingerprint left in the bogus reply, the IDS immediately knows that the
traffic corresponds to an attacker (assuming it correctly identified the
initial recon scan as reflecting an attacker); hence, "no false positives".

Disclaimer: I'm on Forescout's technical advisory board, hence have a
direct interest in the company.  (Anti-disclaimer: I joined their board
because I do think their technology is cool. :-)

                Vern


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]