LogAnalysis
[logs] SIM solution - Objectives ? May 24 2007 05:52AM
saudi sans (saudisans gmail com) (3 replies)
Re: [logs] SIM solution - Objectives ? May 25 2007 08:12AM
Tom Le (dottom gmail com)
Re: [logs] SIM solution - Objectives ? May 24 2007 01:43PM
Paul Melson (pmelson gmail com)
Re: [logs] SIM solution - Objectives ? May 24 2007 12:58PM
Ron Gula (rgula tenablesecurity com) (1 replies)
Re: [logs] SIM solution - Objectives ? May 25 2007 01:29PM
saudi sans (saudisans gmail com) (3 replies)
Re: [logs] SIM solution - Objectives ? May 28 2007 02:33AM
Mordechai T. Abzug (morty frakir org)
RE: [logs] SIM solution - Objectives ? May 25 2007 06:47PM
Tina Bird (tbird precision-guesswork com) (1 replies)
RE: [logs] SIM solution - Objectives ? May 28 2007 01:00AM
Marcus J. Ranum (mjr ranum com) (1 replies)
Here's another point to ponder, which I like to hop up and down about
when I'm doing my "intrusion prevention" workshop at Interop...

When you're setting up your firewall you should design in intrusion
detection by using overlapping permit/deny+LOG rules in the
firewall. It's cheap, fast, *AND* good!

For example, if you have a DMZ and traffic from the DMZ toward
the internal network is getting matched by a default internet
incoming rule - consider installing a superceeding rule that
applies to your DMZ with logging turned on. That way you get
notified when your web server starts strobing SSH ports on
internal hosts. :) Or, perhaps an superceeduing
outbound deny +LOG rule from your DMZ to the internet for
everything except the minimum set of services your DMZ
needs.

My preceeding comments should emphatically not be taken
to mean that I think you shouldn't log denies! If it's worth denying,
it's worth logging - and that's a fact. But in today's environment,
with all the HTTP tunnelling crapware and malware, it's really
really really important to be looking at stuff like "top permitted
destinations" and things like that! In fact I strongly recommend
grabbing blacklists from places like squidguard.org and
joining your destinations of permitted HTTP against the
"spyware sites" blacklist to produce lists of internal machines
that are making calls out to such sites. Useful?

mjr.

_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis

[ reply ]
RE: [logs] SIM solution - Objectives ? May 29 2007 08:02PM
Paul Melson (pmelson gmail com)
Re: [logs] SIM solution - Objectives ? May 25 2007 05:50PM
Paul Melson (pmelson gmail com) (1 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 25 2007 06:35PM
Ron Gula (rgula tenablesecurity com) (2 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 27 2007 03:23PM
Paul Melson (pmelson gmail com) (2 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 03:43PM
Dave Ellingsberg (Dave Ellingsberg csu mnscu edu) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 01:31PM
Paul Melson (pmelson gmail com)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 27 2007 09:02PM
Marcus J. Ranum (mjr ranum com) (3 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 07:20PM
Eric Fitzgerald (Eric Fitzgerald microsoft com)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 05:17PM
Chris Brenton (cbrenton chrisbrenton org) (1 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 08:53PM
Marcus J. Ranum (mjr ranum com)
[logs] SIM solution - Objectives ? (Firewall logging) May 28 2007 05:59PM
Fenwick, Wynn (wynn fenwick cgi com) (2 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 07:07PM
Paul Melson (pmelson gmail com) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 03:40PM
Fenwick, Wynn (wynn fenwick cgi com) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 09:25PM
Paul Melson (pmelson gmail com) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 31 2007 07:42PM
Fenwick, Wynn (wynn fenwick cgi com)
[logs] Log Analysis -- Best Practice May 29 2007 06:13AM
harshad mengle wipro com (1 replies)
Re: [logs] Log Analysis -- Best Practice May 30 2007 12:24AM
Ron Gula (rgula tenablesecurity com)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 25 2007 07:22PM
Jimmy Alderson (jimmy alderson gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus