IDS mailing list archives

Re: IDS vs Application Proxy Firewall


From: "Zhihao Tan" <zhihao () root sg>
Date: Wed, 22 Oct 2008 14:30:06 +0800

an application proxy firewall normally looks for packets that do not
behave like how they are supposed to be as defined by the protocol
standards (RFC)..while an IDS looks for signs of an active attack in a
perfectly legitimate packet that is crafted according to standards..of
course..misbehaving packets are normally picked out by an IDS as well.
hope this helps!

2008/10/22 <maash.rajani () gmail com>

Can someone please explain how is an IDS different from an application proxy firewall in terms of what each of them 
looks for in a packet.

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------




--
./Zhihao

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Current thread: