IDS mailing list archives

Re: challenges in capturing Gigabit ethernet


From: Richard Bejtlich <taosecurity () gmail com>
Date: Mon, 2 Jan 2006 15:43:10 -0500

On 12/29/05, Michael J. Semaniuk <mike () semaniuk com> wrote:
This has always been a problem, but I've found that using an IDS load
balancer does a lot to optimize packet inspection for promiscious devices.


If you'd like to try building a commodity HW/SW solution to inspect
and/or collect packets based on characteristics like IP address, IP
protocol, or port, check out my post on using Pf dup-to to build a
distributed traffic collection system.

http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html

Sincerely,

Richard

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------


Current thread: