Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: Intrusion Prevention requirements document

Subject: Re: Intrusion Prevention requirements document
Date: Mon, 14 Nov 2005 19:25:08 -0800
Sorry for being late to the party...

I think what most people are forgetting about replay tools is that
they're an easy way to CYA before you deploy a box inline on your
network.  Tomahawk, tcpreplay, and Traffic IQ all support taking
pcap's of traffic captured on *your network* and running it through
the IPS/whatever.

If you've ever wondered about things like:
- Is there legit traffic running on my network that this vendor
incorrectly tags/drops as malicous?
- Will this device fall over under load due to odd traffic patterns
that occur on my network?

Then I would suggest using a replay tool to find out since we all know
that forwarding traffic forces the IPS/whatever to do more work then
just sitting there and sniffing traffic on a tap/SPAN port.

Replay tools are also great ways to do repeatable tests of malicous
traffic since they support emulating the client and server side of the
connection.  Once you capture malicous traffic (which may crash the
target or worse) you can replay that traffic in an enclosed testbed
without worrying about having to "fix" the target for the next attack.
 Not useful in every situation, but there are cases where this is
useful (think automated regression testing).

Are replay tools the end-all and be-all of security tools?  Hell no. 
And of course you can use a replay tool in a manner which negates
their usefulness; just because you *can* do something doesn't mean
it's valid for your environment.

Regards,
Aaron (who's somewhat biased as the author of the tcpreplay suite)

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>