IDS mailing list archives

Re: Active response... some thoughts.


From: "andre" <andreq () infolink com br>
Date: Sat, 8 Feb 2003 19:50:21 -0200

What about blocking only a few certain attacks, that could not be easily
spoofed. Such like HTTP vulnerabilities and others that need a complete
handshake to work.

Ok,its not impossible to spoof, but packet sequence prediction is a bit hard
nowadays.

From: Chris Travers [mailto:chris () travelamericas com]
Sent: Wednesday, February 05, 2003 8:16 AM
To: Thomas H. Ptacek
Cc: Focus-IDS
Subject: Re: Active response... some thoughts.


Thomas;

I was also thinking about a liability from a poorly implimented system
being
able to be used to DOS an address by spoofing packets from that address.

I guess I come back to advocating passive solutions primarily.

Best Wishes,
Chris Travers




Current thread: