ForeScout pitches honeypot technology as IPS - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Additional Resources

RSS

FEATURED WHITEPAPERS

Auditing and Recovery for Active Directory: What's New in Windows Server 2008 NetPro

Windows Server 2008 is not intended to be a "one size fits all" solution and Microsoft relies on third-party solutions to enhance and extend Windows Server 2008 to accommodate functions like auditing, backup and recovery. Here, we look specifically at audit and recovery capabilities for Active Directory and learn where Windows Server 2008 toolset leaves off, and where the right third-party solution can provide broader coverage and enhanced management capabilities.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Get Real-world Advice on how to Cost Effectively Consolidate your Data Center Novell

Discover the benefits of paravirtualization in this informative webcast today. This server virtualization-themed webcast not only explores how to improve virtualized server performance, but provides real-world user examples, explains how to optimize workloads and discusses the future of server virtualization. Focus on only the themes that interest you or watch all six consecutively for a full picture of how you can lower your costs significantly through consolidation and virtualization. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

ForeScout pitches honeypot technology as IPS

By Joel Snyder and Christine Burns , Network World , 02/16/2004
  • Social Web 
  • Email 
  • Feedback 
  • Close
IPS in the Wild

While we found 11 vendors that met our criteria for in-line network-based intrusion-protection systems, yet more vendors still wanted to be tested even though their products, though interesting, don't quite fit the bill.

One that caught our attention was ForeScout Technologies' ActiveScout. In our experience with the product - we had it up an running in front of our production network for several months in early 2003 - we found ActiveScout to be a kind of honeypot that can be used to efficiently identify and block traffic from the automatic attack tools that most amateur hackers use.

ActiveScout sits in the network on a monitoring port, typically outside the corporate firewall. ActiveScout has no real services and protects no real systems. Instead, it simulates a variety of applications that could be interesting to attackers. The theory is that anyone who connects to one of these simulated applications is up to no good. At that point, ActiveScout uses its monitoring capabilities to attempt to reset any TCP connections from the attacker and reprogram the corporate firewall to block traffic. ActiveScout can take this a step further by feeding back "poison" information to the attacker, such as a particular NETBIOS name. If connection attempts show up from other sources with this poison information in hand, ActiveScout will block traffic from those sources as well.

The benefit to ForeScout's approach is pretty clear: no false positives. Because you're not looking for a signature or any other protocol anomaly, you don't have to worry about misdetecting potential attacks. It's behavioral: Anyone touching that box must be bad and stopped.

What ForeScout doesn't advertise is the flip side of no false positives: Lots of false negatives. Only someone who actually does reconnaissance using this model will get caught. If the bad guys already know where the Web server is - maybe they looked it up in the DNS - ActiveScout won't do anything about the attack, successful or not.

Nevertheless, the great majority of Internet attacks, what we called "background radiation," use a pattern that is susceptible to the kind of technology ForeScout brings to the table. This is why some of the IPS tools we looked at (from NetScreen and EcoNet.com) include honeypot features as well, although not with ActiveScout's level of sophistication.

1 | 2 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code
IT Buyer's Guides

View All Buyer's Guides