Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: TrafficIQ HTTP IE traffic coverage |
|---|---|
| Date: | Wed, 11 Oct 2006 10:50:58 -0600 |
On Oct 10, 2006, at 1:40 AM, SanjayR wrote:
Hi All:
Few days ago, I got a chance to work on TrafficIQ (karalon IDS/IPS evaluation device). With its latest update, Traffic IQ has traffic for many attacks. A majority of HTTP traffic is related to IE crash (or DoS). I have a doubt at this point. TrafficIQ is used to evaluate IDS/IPS, which in turn is used to detect the sign of attacks and at the same time, it should not become a bottleneck (esp. IPS) by taking too much time to process packets. Therefore, the signatures should be optimized well, which implies that number of signatures should be kept as minimum as possible without compromising the internal network security. From this standpoint, I have an opinion that all the IE (or other clients) crash or DoS related signatures should have lowest priority, because as such these attacking activities are not doing any harm to internal network. (I may go a little further to say, such signatures are not required!!!). One is going to a site which contains a malicious file that causes IE to crash. so what..don't go or don't download that.. anyway that file is bad.
If my assumption is correct and justified, then TrafficIQ, as an IDS/IPS evaluation tool, should not contain such traffic. Such traffic, as such, does not evaluate capabilities of an IDS/IPS effectively. Has TrafficIQ included such traffic just to advertise its high number of various attacks?
Please let me know if i have gone wrong with my assumtion.
thanks
Sanjay Security Research Engineer INTOTO Software (India) Private Limited
---------------------------------------------------------------------- --
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5? module=Form&action=impact&campaign=intro_sfw to learn more.
---------------------------------------------------------------------- --
------------------------------------------------------------------------ Test Your IDS
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | New IPS testing methodology, Bob Walder |
|---|---|
| Next by Date: | Re: Re: TrafficIQ HTTP IE traffic coverage, Sanjay R |
| Previous by Thread: | TrafficIQ HTTP IE traffic coverage, SanjayR |
| Next by Thread: | Re: TrafficIQ HTTP IE traffic coverage, Abhishek Bhuyan |
| Indexes: | [Date] [Thread] [Top] [All Lists] |