Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







IDS: Re: Email reputation for inout to IDSs?

Re: Email reputation for inout to IDSs?

From: Tremaine Lea <focus-ids_at_ddiction.com>
Date: Wed, 26 Nov 2008 11:53:12 -0700

On 26-Nov-08, at 8:37 AM, Joel Snyder wrote:

> There are a few IPS/IDS solutions out there utilizing email reputation
> > as part of their solutions, and they primarily get their strength
> from a
> > centralized managed db on the part of the vendor supplying the
> solution.
>
> I haven't seen this actually happening; do you have specific
> products in mind? Other than 'intention,' it doesn't seem to have
> been rolled out yet.

I'm drawing a blank on the vendor, it came up when we were evaluating
UTM solutions. It may have been Juniper or Checkpoint, I don't recall
and am unable to devote the time to dig back at the moment I'm
afraid. The other possibility is Tipping Point, but again I'm having
a morning where my recollection is a bit hazy ;)

I'm definitely interested in seeing how the various vendors address
this from an architecture design stance, and particularly how much
flexibility they provide to the client in making choices with regards
to the reputation information. Also be interesting to see if this
gets extended beyond email reputation to straight IP reputation,
perhaps utilizing information similar to that found on MyNetWatchMan
or sites like ISC.

Cheers, and thanks for the well thought out response - it was a good
read!

---
Tremaine Lea
Network Security Consultant
Intrepid ACL
Paranoia for hire
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------
Received on Nov 26 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]