Information Security News mailing list archives

Several security related articles


From: InfoSec News <isn () C4I ORG>
Date: Thu, 14 Sep 2000 10:35:46 -0500

Forwarded By: "Berislav Kucan BHZ" <bhz () net-security org>

[Articles weren't posted here in txt format, because they are in rtf/pdf format]

Network Intrusion Detection of Third Party Effects
by: Richard Bejtlich

The main goal of this paper by Richard Bejtlich is to familiarize the
reader with reactions and responses from innocent victims, who may be
subject to reconnaissance or denial of service. If a perpetrator
spoofs your address space you may see unsolicited traffic from an
innocent second party.  Link:
http://www.net-security.org/text/articles/index-download.shtml#NID


Building a Bastion Host Using HP-UX 11
by: Kevin Steves

A bastion host is a computer system that is exposed to attack, and may
be a critical component in a network security system. Special
attention must be paid to these highly fortified hosts, both during
initial construction and ongoing operation. This paper presents a
methodology for building a bastion host using HP-UX 11. While the
principles and procedures can be applied to other HP-UX versions as
well as other Unix variants, the focus is on HP-UX 11. Link:
http://www.net-security.org/text/articles/index-download.shtml#HP-UX


Interpreting Network Traffic: A Network Intrusion Detector's Look At
Suspicious Events
by: Richard Bejtlich

The purpose of this paper is to discuss interpretations of selected
network traffic events from the viewpoint of a network intrusion
detection analyst. I assume the analyst has no knowledge of the source
of the event outside of the data collected by his network-based
intrusion detection system (NIDS) or firewall logs. I do not
concentrate on the method by which these events are collected, but I
assume it is possible to obtain data in TCPDump format.

Link:
http://www.net-security.org/text/articles/index-download.shtml#intrusion

Cheers,

Berislav Kucan
bhz () net-security org
http://net-security.org

ISN is hosted by SecurityFocus.com
---
To unsubscribe email LISTSERV () SecurityFocus com with a message body of
"SIGNOFF ISN".


Current thread: