|
IDS
mailing list archives
Re: challenges in capturing Gigabit ethernet
From: Richard Bejtlich <taosecurity () gmail com>
Date: Mon, 2 Jan 2006 15:43:10 -0500
On 12/29/05, Michael J. Semaniuk <mike () semaniuk com> wrote:
This has always been a problem, but I've found that using an IDS load
balancer does a lot to optimize packet inspection for promiscious devices.
If you'd like to try building a commodity HW/SW solution to inspect
and/or collect packets based on characteristics like IP address, IP
protocol, or port, check out my post on using Pf dup-to to build a
distributed traffic collection system.
http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html
Sincerely,
Richard
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------
By Date
By Thread
Current thread:
|