Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Intrushield vs. ISS once more... |
|---|---|
| Date: | Wed, 5 Jan 2005 10:24:19 -0500 |
Regarding "psychic packet capture" (an aptly named feature):
Let me take a stab:
Double these numbers if you're tracking both sides of the connection.
Probably because it isn't very useful.
For instance:
How hard do you think a system like this would be to attack?
On Dec 31, 2004, at 4:16 AM, Maynor, David (ISS Atlanta) wrote:
Lancope product called Therminator. It incorporates a process they call
"psychic packet prediction." This attempts to maintain a certain buffer
of every connection. I can't remember the number; I think 50 packets or
so. When something in that buffer causes an alarm the entire buffer is
saved so not only do you get the packets that caused the alarm, you get
a certain amount ahead and behind it. This helps with forensics greatly.
--- Thomas H. Ptacek // Product Manager, Arbor Networks (734) 327-0000
-------------------------------------------------------------------------- Test Your IDS
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Intrushield vs. ISS once more..., Chris Mills |
|---|---|
| Next by Date: | IDS Evaluation, naga raj peddisetty |
| Previous by Thread: | RE: Intrushield vs. ISS once more..., Maynor, David (ISS Atlanta) |
| Next by Thread: | Re: Intrushield vs. ISS once more..., Dennis Cox |
| Indexes: | [Date] [Thread] [Top] [All Lists] |