Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




focus-ids logo IDS mailing list archives

Re: Active response... some thoughts.
From: Chris Travers <chris () travelamericas com>
Date: Fri, 31 Jan 2003 10:22:58 -0800

Hi--

I had an additional idea relating to quasi-active response.  For example--

An IDS could have hooks into a routers filtering tables in order to temporarily ban that IP address. This has the advantage of the RST in that all inbound traffic from the attacker would be stopped, but would create less traffic on the gateway than a RST would. Additionally this could also be used against connectionless protocols such as UDP and ICMP.

It is more flexible, could be implimented on a timer to minimize the damage of false alarms, etc.

Best Wishes,
Chris


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]