|
Donations |
|
|
|
|
|
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
|
|
|
Survey |
|
|
|
|
|
|
|
|
Translate |
|
|
|
|
|
|
|
|
|
|
View previous topic :: View next topic |
Author |
Message |
SheepExplode
Cadet
Joined: Jun 02, 2004
Posts: 4
Location: USA
|
Posted: Thu Jun 03, 2004 12:25 pm Post subject: Behavior based tools |
|
|
So there is the Cisco Secure Agent, ISS has something they call Proventia Intrusion Prevention, Microsoft announced they will be coming out with a behavior based tool next year and let’s not forget PivX's Qwik-Fix Pro. Does anyone have details on the differences between all these products? How they differ, how they are alike, who uses what technology, whose is better? I know that you can bypass the CSA using a shatter attack, and common sense says that if you use a tool that is controlled by a computer that expects certain behavior and stops any unexpected behavior with a few more steps I could bypass this model, I as an admin have the ability to copy, delete, request traffic on port 21 or 80, map a network drive, delete files on a network drive, copy files to a mapped drive, etc. So I guess my real question is is this just a fad wrapped in a lot of jargon? Are we going to see the "new security" model defeated like CD write protection? Why should I spend $100k to buy something that some kids or spyware companies are going to defeat?
Regards. |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
|
Powered by phpBB 2.0.8a © 2001 phpBB Group
Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops
|