IDS mailing list archives
Re: challenges in capturing Gigabit ethernet
From: Richard Bejtlich <taosecurity () gmail com>
Date: Mon, 2 Jan 2006 15:43:10 -0500
On 12/29/05, Michael J. Semaniuk <mike () semaniuk com> wrote:
This has always been a problem, but I've found that using an IDS load balancer does a lot to optimize packet inspection for promiscious devices.
If you'd like to try building a commodity HW/SW solution to inspect and/or collect packets based on characteristics like IP address, IP protocol, or port, check out my post on using Pf dup-to to build a distributed traffic collection system. http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html Sincerely, Richard ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Current thread:
- Re: challenges in capturing Gigabit ethernet Michael J. Semaniuk (Jan 02)
- Re: challenges in capturing Gigabit ethernet Richard Bejtlich (Jan 05)
- <Possible follow-ups>
- Re: challenges in capturing Gigabit ethernet Securesolutions (Jan 02)
- Re: challenges in capturing Gigabit ethernet Stefano Zanero (Jan 05)