Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Checkpoint SmartDefense |
|---|---|
| Date: | Wed, 18 May 2005 23:53:18 +0100 |
-----Original Message----- From: Fergus Brooks [mailto:fergwa@gmail.com] Sent: quarta-feira, 18 de Maio de 2005 12:10 To: focus-ids@securityfocus.com Subject: Checkpoint SmartDefense Hi all, I am getting some mixed messages regarding this feature. 1) Does it detect zero day attacks in real time and recommend/implement remediation
It can detect some attacks on the fly and stop them.
2) How intelligent is it?
It depends a lot on the type of filtering made. For instance, some DNS queries are mistaken with DNS buffer overflow attempts, probably because they're not RFC compliant. The same problem happens with other protocols. On the other hand it successfully filters most common DoS attacks and worms (Land, code red & friends)
3) Is it difficult to configure & maintain?
IMHO, Like most checkpoint products the difficulty is the *installation* phase. SmartDefense however, can be very tricky to *tune*, but not to configure, as the default configuration doesn't harm a fly.
4) Is this feature different on the Interspect and standard FW-1 boxes
Dunno, I'm only using it in a Nokia IP firewall (over their IPSO), and it seems quite happy.
Any comments and real world examples greatly appreciated!
It doesn't replace nice PC boxes running snort, and other IDS tools. In fact, is advisable to have a network setup with both. Some Smartdefense features can cause very obscure errors. I remember having problems with the Autodesk Mapguide server and Mapguide agent, because the communication protocol designed by Autodesk was mistaken with the blaster Worm. Then again I'm using a 2003 version of smartdefense. The product could have been improved a lot by now. -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Packet/Protocol Anomaly Detection with IDS, Frlinger |
|---|---|
| Next by Date: | Re: Vulnerability vs. Exploit signatures and IPS??, David W. Goodrum |
| Previous by Thread: | Checkpoint SmartDefense, Fergus Brooks |
| Next by Thread: | RE: Checkpoint SmartDefense, Dimitrios Patsos |
| Indexes: | [Date] [Thread] [Top] [All Lists] |