Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Definition of Zero Day Protection |
|---|---|
| Date: | Mon, 09 Aug 2004 18:42:16 -0500 |
----- Original Message ----- From: "Teicher, Mark (Mark)" Date: Mon, 9 Aug 2004 13:14:45 -0600 To: "Drew Simonis" , Subject: RE: Definition of Zero Day Protection
Drew, What host based products would fit this category based on the definition
I know that Cisco tries to position their "Cisco Security Agent" product in the 0 day blocking space, as it uses behavior blocking. I've also seen Symantec Manhunt (NIDS, but...) claiming to offer 0 day detection based on protocol detection. I don't think Symantec Host IDS offers the sort of behavior blocking yet, but it does support white listing to restrict application execution, which would offer some 0 day protection. I am not familiar with other offerings.
?? Do they really work ??
As mentioned, do we consider them working if, at 100% malicious detection, they lump in 20% non-malicious false positive? (of course, I am making these numbers up). I think, until the FP rate is reduced drastically, this sort of blocking technology (including IPS) is more marketing than mainstream. I don't trust the products to do what they say, and only what they say. -Ds -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Post Script RE: Definition of Zero Day Protection, Drew Copley |
|---|---|
| Next by Date: | RE: Definition of Zero Day Protection, Drew Copley |
| Previous by Thread: | RE: Definition of Zero Day Protection, Brian Smith |
| Next by Thread: | Re: Definition of Zero Day Protection, Stefano Zanero |
| Indexes: | [Date] [Thread] [Top] [All Lists] |