IDS mailing list archives
Re: Intrusion Prevention
From: Karl Lynn <klynn () stackheap org>
Date: Wed, 11 Dec 2002 14:35:33 +0000 (GMT)
Their product seems to be based on initial recon and only then does it make a decision to thwart the event. So, lets say you have 2 shell accounts, one does the recon, the other does the actual attack both on totally different networks. I'm wondering how this would effect this product. I haven't personally evaluated ActiveScout but to make claims of 100% no false positives is a very bold statement and usually to mitigate the false positives of any IDS there must be some sort of tuning involved with the product. Anyhow, it looks like you send some recon and this product intercepts it and sends back "valid" information which is called a "mark" then if ActiveScout sees this "mark", it blocks the attack. Im curious as to how they are going to mark an attack in which they have no idea what im sending. Even more so like I stated above using two totally different networks, one for recon and the other for the actual compromise. Just some thoughts... -Karl On Thu, 5 Dec 2002 intrusi0n () cox net wrote:
Hello everyone, Has anyone here seen or used ActiveScout, by ForeScout technologies? It claims to have a 100% accuracy , no false positives. I am rather skeptical, but I was wondering if anyone here has any expertise using or evaluating this. Any input is greatly appreciated! ()()()()()
Current thread:
- Intrusion Prevention intrusi0n (Dec 08)
- Re: Intrusion Prevention Paul Wayne Brager Jr (Dec 09)
- Re: Intrusion Prevention Raistlin (Dec 09)
- Re: Intrusion Prevention roy lo (Dec 10)
- Re: Intrusion Prevention Karl Lynn (Dec 11)
- <Possible follow-ups>
- RE: Intrusion Prevention Avi Chesla (Dec 09)
- Re: Intrusion Prevention Jill Tovey (Dec 09)
- Re: Intrusion Prevention Frank Knobbe (Dec 10)
- RE: Intrusion Prevention Adam Powers (Dec 10)
- RE: Intrusion Prevention Ralph Los (Dec 10)
- Re: Intrusion Prevention Vern Paxson (Dec 10)
- RE: Intrusion Prevention Chris Petersen (Dec 11)
- Intrusion Prevention Johnny Kho (Dec 23)
- RE: Intrusion Prevention Robert_Huber (Dec 11)
- RE: Intrusion Prevention Matthew L. McGuirl (Dec 11)
(Thread continues...)
