IDS mailing list archives

RE: Denial of Service: Commercial Defense products


From: "Talisker" <lists () securitywizardry com>
Date: Fri, 25 Nov 2005 21:37:43 -0000

Hi Ogle,
Apologies for the late response I've been on the road.
Firstly the text on the page may be a little dated, much of the technology
has marched on and some products are now good at both. I would suggest and
probably get flamed for it, that the IPS have adapted to handle rate than
vice versa.  I'm playing with a particular IPS (unnamed)currently that is
very effective at dealing with DDOS

Andy Cuff
Chief Technology Officer
Computer Network Defence Ltd
http://www.securitywizardry.com

07010 709014
 

-----Original Message-----
From: Ogle [mailto:myinfosec () gmail com]
Sent: 24 November 2005 08:46
To: Talisker
Cc: focus-ids () securityfocus com
Subject: Re: Denial of Service: Commercial Defense products

Hi Andy,
My customer stated that they want to mitigate DDoS. Referring to your
page, "...NIPS are not always necessarily good at mitigating DOS/DDOS
attacks....". Does it mean, that I could not replace it with IPS ?

Ogle


On 11/24/05, Talisker <lists () securitywizardry com> wrote:
Hi Ogle,
Nice list of products, I'm missing a few and would like to use your
information.  I have independent details on many other attack mitigation
systems at http://www.securitywizardry.com/idsdosmit.htm these are
predominantly rate based products, it may also be worth you looking at
the
increasing number of Intrusion Prevention Systems that possess a hybrid
combination of both rate and content based protection these are listed
at
http://www.securitywizardry.com/inline.htm the overheads in managing and
monitoring the latter products are a little higher but well worth the
investment

Good luck

Andy Cuff
Chief Technology Officer
Computer Network Defence Ltd
http://www.securitywizardry.com

07010 709014



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------


Current thread: