Firewall Wizards mailing list archives

RE: firewalls and the incoming traffic problem


From: Bill Stout <stoutb () pios com>
Date: Fri, 10 Oct 1997 14:02:10 -0700

At 12:08 PM 10/7/97 -0700, Phil Cox wrote:
At 12:15 PM 9/30/97 -0700, you wrote:
...
What is the thought on the ability to write a firewall specific IDS which
would use some type of meta language to define what was considered
"acceptable" for different services coming across a firewall. The the IDS

See NetRanger and NetSentry (http://www.network.com/NetSentry/ ).  NetRanger
is the IDS system (sensors & a director), NetSentry runs in the 'firewall'
which dynamically responds to NetRanger commands in response to detected
intrusions.

Or are you talking about an industry standard?  If one figured out how to
hijack a standardized IDS->FW dynamic rule link (or a proprietary one), it
would make for some interesting D.O.S.s.  Hmm, look like an IDS->FW
communication link, and it doesn't detect you as an attack...

Bill Stout




Current thread: