New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1157
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Behavior based tools

 
Post new topic   Reply to topic       Computer Cops Forum Index -> General Security
View previous topic :: View next topic  
Author Message
SheepExplode

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 4
Location: USA

PostPosted: Thu Jun 03, 2004 12:25 pm    Post subject: Behavior based tools
Reply with quote

So there is the Cisco Secure Agent, ISS has something they call Proventia Intrusion Prevention, Microsoft announced they will be coming out with a behavior based tool next year and let’s not forget PivX's Qwik-Fix Pro. Does anyone have details on the differences between all these products? How they differ, how they are alike, who uses what technology, whose is better? I know that you can bypass the CSA using a shatter attack, and common sense says that if you use a tool that is controlled by a computer that expects certain behavior and stops any unexpected behavior with a few more steps I could bypass this model, I as an admin have the ability to copy, delete, request traffic on port 21 or 80, map a network drive, delete files on a network drive, copy files to a mapped drive, etc. So I guess my real question is is this just a fad wrapped in a lot of jargon? Are we going to see the "new security" model defeated like CD write protection? Why should I spend $100k to buy something that some kids or spyware companies are going to defeat?

Regards.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> General Security All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops