Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Intrusion Prevention requirements document |
|---|---|
| Date: | Mon, 14 Nov 2005 19:25:08 -0800 |
Sorry for being late to the party... I think what most people are forgetting about replay tools is that they're an easy way to CYA before you deploy a box inline on your network. Tomahawk, tcpreplay, and Traffic IQ all support taking pcap's of traffic captured on *your network* and running it through the IPS/whatever. If you've ever wondered about things like: - Is there legit traffic running on my network that this vendor incorrectly tags/drops as malicous? - Will this device fall over under load due to odd traffic patterns that occur on my network? Then I would suggest using a replay tool to find out since we all know that forwarding traffic forces the IPS/whatever to do more work then just sitting there and sniffing traffic on a tap/SPAN port. Replay tools are also great ways to do repeatable tests of malicous traffic since they support emulating the client and server side of the connection. Once you capture malicous traffic (which may crash the target or worse) you can replay that traffic in an enclosed testbed without worrying about having to "fix" the target for the next attack. Not useful in every situation, but there are cases where this is useful (think automated regression testing). Are replay tools the end-all and be-all of security tools? Hell no. And of course you can use a replay tool in a manner which negates their usefulness; just because you *can* do something doesn't mean it's valid for your environment. Regards, Aaron (who's somewhat biased as the author of the tcpreplay suite) ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: File-format based vulns - How do vendors detect them?, Palmer, Paul (ISSAtlanta) |
|---|---|
| Next by Date: | RE: Experience security-information-management, José Luis Jerez |
| Previous by Thread: | RE: Intrusion Prevention requirements document, Chris Ralph |
| Next by Thread: | IPv6 support in IDS/IPS products, David Williams |
| Indexes: | [Date] [Thread] [Top] [All Lists] |