TIP: Click on subject to list as thread! ANSI
echo: bbs_carnival
to: mark lewis
from: Sampsa Laine
date: 2011-03-04 21:11:00
subject: Re: Fidonet and today

-=> mark lewis wrote to Sampsa Laine <=-

 ml> this is known as an IDS, Intrusion Detection System... snort is the
 ml> current base one being used... surricata is breaking new ground and
 ml> coming up, though...

 ml> both products scan the stream... they don't really care about the
 ml> "level"... they also have the ability to scan encrypted streams,
 ml> IIRC... i know my IDS set up does and warns be about things while it is
 ml> slamming the door shut on others ;)

Sure - deep packet inspection is typically a combination of IDS/IPS and
a stateful firewall. 

As for scanning encrypted streams, not sure how exactly that would work
without some kind of man in the middle attack. Encrypted is just that, 
if I connect over say SSH to you across this IDS, there is no way the
IDS can tell our traffic from random noise (provided the SSH implementation
isn't faulty and we don't get MITM'd somehow by the IDS - which is a 
security problem in itself).

 

... MultiMail, the new multi-platform, multi-format offline reader!
--- MultiMail/Darwin v0.49
--- SBBSecho 2.11-Win32
* Origin: B4BBS = London = b4bbs.sampsa.com 2:250/7 (2:250/7)
SEEN-BY: 3/0 633/267 640/954 712/0 313 550 620 848
@PATH: 123/500 261/38 712/848 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.