Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




focus-ids logo IDS mailing list archives

Re: Active response... some thoughts.
From: Chris Travers <chris () travelamericas com>
Date: Tue, 04 Feb 2003 23:16:08 -0800

Thomas;

I was also thinking about a liability from a poorly implimented system being able to be used to DOS an address by spoofing packets from that address.

I guess I come back to advocating passive solutions primarily.

Best Wishes,
Chris Travers

Thomas H. Ptacek wrote:

On 1/31/03 1:22 PM, "Chris Travers" <chris () travelamericas com> wrote:

An IDS could have hooks into a routers filtering tables in order to
temporarily ban that IP address.  This has the advantage of the RST in
that all inbound traffic from the attacker would be stopped, but would

ACL countermeasures are generally avoided because it is hard to make them
fail safely. It is not easy to push soft-state ACLs to Cisco and Juniper
routers; the risk that the IDS could get desynchronized from the filter is
large.







  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]