|
Does Verizon's Voyager stack up to the iPhone? |
|
|
5 IT skills that won't boost your salary
[1,407]
Women 4 times more likely than men to cough up personal info
[589]
Japan's 10 funniest tech-related commercials [Videos]
[407]
Throwing away a promo CD is "unauthorized distribution"?
[1,265]
Adults too quick to dismiss educational video games
[682]
Attack of the iPhone clones [Slideshow]
[578]
10 things IT needs to know about AJAX
[1,258]
This Year's 25 Geekiest 25th Anniversaries [Slideshow]
[409]
|
|
RE: Six ways to fight back against botnets
Suggestion 4 (deploy IPS/IDS) mixes up IPS and NBA, which are different types of products. Network Behavioral Anomaly (NBA) systems look for unusual traffic activity. As you point out, they're good for detecting suspicous activity, but be aware that they require some care and feeding -- an analyst must validate that the suspicious activity is due to malware. Intrusion Prevention Systems detect previously installed bots/spyware/malware and prevent their installation in the first place. Many examine the HTTP payload in the return traffic to look for known or suspicious content, including attacks such as cross site scripting. Not all IPSs have these features, so be sure to ask the vendor about their spyware capabilities before buying.