nanog mailing list archives

Re: and here are some answers [was: Quarantine your infected users spreading malware]


From: Jim Segrave <jes () nl demon net>
Date: Tue, 21 Feb 2006 12:26:00 +0100


On Tue 21 Feb 2006 (04:15 +0200), Gadi Evron wrote:

Christopher L. Morrow wrote:
it's also not just a 'i got infected over the net' problem... where is
that sean when you need his nifty stats :) Something about no matter what
you filter grandpa-jones will find a way to click on the nekkid jiffs of
Anna Kournikova again :(

anyway, someone mentioned the rafts of posts in the archives, it'd be nice
if this was all just referred there :(

I quite agree, unless other solutions can be presented, and indeed, 2 
new ones have so far.

The philosophical discussion aside (latest one can be found under "zotob 
port 445 nanog" on Google), presenting some new technologies that shows 
this *can* be done changes the picture.

http://www.quarantainenet.nl/

It works, we use it. It cuts down on support calls, customers
generally react well to it and, at least when using Juniper core routers,
it's not too intrusive in the network and will scale to pretty large
networks of users.

-- 
Jim Segrave           jes () nl demon net


Current thread: