Network World
Monday, December 1, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

RE: Six ways to fight back against botnets

0

Suggestion 4 (deploy IPS/IDS) mixes up IPS and NBA, which are different types of products. Network Behavioral Anomaly (NBA) systems look for unusual traffic activity. As you point out, they're good for detecting suspicous activity, but be aware that they require some care and feeding -- an analyst must validate that the suspicious activity is due to malware. Intrusion Prevention Systems detect previously installed bots/spyware/malware and prevent their installation in the first place. Many examine the HTTP payload in the return traffic to look for known or suspicious content, including attacks such as cross site scripting. Not all IPSs have these features, so be sure to ask the vendor about their spyware capabilities before buying.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: