Re: PSD comments

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



El vie, 25-02-2005 a las 17:37 +0530, hareram escribiÃ:
> Hi all
> 
> 
> iam planning to deploy Portscan Detect module
> at my back bone
> 
> how far this module can work with my 100MB network
> or i need to Look for IDS
> 
> does any one put some coments on this
> 
> hare
> 

My personal experience says you better try an IDS, it's
much more capable of detecting portscans. But if you
want to stop some of them you can also have some rules
to stop some TCP flags combinations that identifies
portscans.

Regards.

-- 

Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac@xxxxxxxxx
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÃA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"





[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux