Focus on IDS
Re: IDS vs Application Proxy Firewal Oct 24 2008 10:02PM
alfredhuger (at) winterhope (dot) com [email concealed] (alfredhuger winterhope com) (1 replies)
Arian,

>Anyway, that said, the behavioral realm
>is begging to be explored more. I'm surprised
>none of the vendors have touched it. It
>seems so promising.

They have, the problem is in finding market applicability. This
approach (and I expand this to behavioral protection in general) tends
to be imprecise enough to require marriage to more direct methods like
white listing and black listing. Simply put the false positive rates
(when the technology is deployed in isolation) suck. Paying customers
tend to have a pretty limited tolerance for that so the tech tends to
get buried and becomes a victim of underemphasis. Hopefully the open
source community will dig in and fix this for everyone else so they
can profit on it.

>ps -- unsure if this will make the list. Security
>Focus has randomly blocked me from some
>lists but not others, and I have been unable
>to get the SF list-server admins to respond
>to email about this for almost TWO YEARS
>now for some reason.

For a guy who is obviously quite intelligent I'm surprised you've not
sorted this one out yet. Your posts are certainly well thought out and
you clearly understand your space well. The gating factor for you ( or
more precisely, your posts) is that you litter your posts with
frenetic vitriol. In an otherwise fantastic post you make two cheap
(albeit possibly true) shots at vendors in the app firewall/ids space
and then follow up with a coup de grace at the site your posting
through. All of this and your surprised your posts fail and the
moderators ignore you?

al

------------------------------------------------------------------------

Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
to learn more.
------------------------------------------------------------------------

[ reply ]
Re: IDS vs Application Proxy Firewal Oct 25 2008 09:29AM
Damiano Bolzoni (damiano bolzoni utwente nl) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 27 2008 04:39PM
Omar Herrera (oherrera prodigy net mx) (2 replies)
Re: IDS vs Application Proxy Firewal Oct 27 2008 08:59PM
Arian J. Evans (arian evans anachronic com) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 28 2008 03:21AM
Omar Herrera (oherrera prodigy net mx) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 28 2008 10:44PM
Arian J. Evans (arian evans anachronic com)
Re: IDS vs Application Proxy Firewal Oct 27 2008 08:28PM
Stefano Zanero (zanero elet polimi it) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 28 2008 02:33AM
Omar Herrera (oherrera prodigy net mx) (2 replies)
Re: IDS vs Application Proxy Firewal Oct 28 2008 03:04PM
Damiano Bolzoni (damiano bolzoni utwente nl)
Re: IDS vs Application Proxy Firewal Oct 28 2008 02:22PM
Stefano Zanero (zanero elet polimi it) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 28 2008 11:37PM
Ashish Kamra (akamra purdue edu) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 29 2008 04:07PM
Stefano Zanero (s zanero securenetwork it) (1 replies)
RE: IDS vs Application Proxy Firewal Oct 29 2008 04:54PM
Kamra, Ashish (akamra purdue edu) (1 replies)
Re: IDS vs Application Proxy Firewal Oct 29 2008 07:55PM
Stefano Zanero (zanero elet polimi it)


 

Privacy Statement
Copyright 2010, SecurityFocus