funsec mailing list archives

Re: s00per firewall


From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Fri, 14 Jul 2006 18:45:04 -0400

On 7/14/06, C Q <kyle.c.quest () gmail com> wrote:
Nothing really special or new... they didn't even do their research well
when it comes to the existing solutions... especially the commercial
ones and for the commercial systems they looked at they usually
didn't understand how they worked (word "unclear" or "not clear" show
up in more than one place) sometimes saying that those products
don't have an open API to be integrated within a larger system.
Good for them though... They were able to get some money
and build a fun toy.



Is that the best method for combating DoS and botnets though? Creating
a DB of hosts and logging their patterns of activity?

Is their an algorithm of "normal" net activity you can apply to
different IP blocks based on who resells them? Do consumer blocks act
with a general measure of a certain type of activity?

It seems like a promising method IMO

-JP<who may have read too much into it>

-JP
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: