Firewall Wizards mailing list archives
Re: VPN endpoint
From: anyluser <anyluser () yahoo com>
Date: Tue, 31 Aug 2004 08:41:35 -0700 (PDT)
In the information security case, this is generally numbers pulled out of thin air. The major question that remians is: As a infosec professional, how do you evaluate the risk of an event happening, given that the real numbers of such events are not available.
I think this is where experience and "knowing the ways
of thy enemy" come into place with a dash of
mentoring. Granted the only information you'll get is
anectdotal but given that IMO Gartner studies are
expensive and about as reliable to me as poll-taking
housewives (mentioned in another message). I have to
rely on my own experience and when I feel that's not
enough I'll lean on the exp of my peers. We're here
for eachother and lists like this one make it possible
for us to share what we know, what we think and most
importantly, what we suspect.
Lets also not forget that we have a window into our
respective networks past. Detailed logging isnt only
there for tracking down a break in and it's important
to emphasize that. Log analysis is a huge part of our
jobs. WRT to known threats, it's not a stretch to
project into future based on events in the past. For
the unknown threats I try to keep a watchfull eye on
the traffic patterns and weigh them against the "feel"
of my territory.
_______________________________
Do you Yahoo!?
Win 1 of 4,000 free domain names from Yahoo! Enter now.
http://promotions.yahoo.com/goldrush
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: VPN endpoint anyluser (Sep 01)
- Logs (was Re: VPN endpoint) Devdas Bhagat (Sep 01)
