Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: TippingPoint Releases Open Source Code for First Intrusion Pr evention Test Tool, Tomahawk |
|---|---|
| Date: | Wed, 3 Nov 2004 10:04:48 -0800 |
Because IDS/IPS companies spend a fair amount of their time/effort tracking down these exploits and capturing them for their internal development, QA and competitive testing. Unlike the AV industry the IDS/IPS industry doesn't work together on detecting new exploits, and hence if company A has a capture/exploit for a new worm before company B then they can write a signature for it sooner and have better coverage then their competition and beat their marketing drum louder. -Aaron -- http://synfin.net/ On Tue, 2 Nov 2004 11:00:58 -0600, Compton, Rich <rcompton@chartercom.com> wrote:
Why the heck would a pcap be confidential? As far as I know the pcaps that would be used in IPS testing would consist of some attack traffic (maybe obfuscated w/ fragrouter) with a mix of valid traffic. You replay the pcap and verify that the attack traffic was blocked. Anybody can generate and record this traffic relatively easily. Would it be because some IPSs work well with certain types of traffic (pcaps) and not very well with others? If so, then the community should share this information and these pcap files to reproduce the results. We could then make better informed decisions about what is the right device to purchase for our networks.
-------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: TippingPoint Releases Open Source Code for FirstIntrusionPrev ention Test Tool, Tomahawk, Martin Roesch |
|---|---|
| Next by Date: | RE: TippingPoint Releases Open Source Code for First Intrusion Pr evention Test Tool, Tomahawk, Maynor, David (ISS Atlanta) |
| Previous by Thread: | RE: TippingPoint Releases Open Source Code for First Intrusion Pr evention Test Tool, Tomahawk, Compton, Rich |
| Next by Thread: | RE: TippingPoint Releases Open Source Code for First Intrusion Pr evention Test Tool, Tomahawk, Ron Gula |
| Indexes: | [Date] [Thread] [Top] [All Lists] |