Showing posts with label IPS. Show all posts
Showing posts with label IPS. Show all posts

Saturday, August 10, 2013

Currently, we can check that many manufacturers of security appliances are writing books "for dummies".  You can get them for free and you can download them in this post.

Notice these books are free because they want to sell you their products, obviously... But many of them are really interesting because they show you how working the Next Generation Firewalls, how the Modern Malware is evolutioning, how we can avoid attacks like Distributed Denials of Firewalls, etc...

I've created a recopilation of many of them...

Click on the pictures to download the books.  If some links are broken, please tell me.

Definitive Guide to Next-Generation Threat Protection FireEye




Intrusion Prevention Systems For Dummies Sourcefire


Oficial link


Modern Malware for Dummies by PaloAlto Networks


Oficial link


Next Generation Firewalls for Dummies by Palo Alto  Networks


Oficial link


UTM for Dummies by Fortinet



DDOS for dummies by Corero


Oficial link


Network Security in Virtualized Data Centers by PaloAlto Networks


Oficial link

Posted on Saturday, August 10, 2013 by Javier Nieto

No comments

Wednesday, April 03, 2013

The last week of March, SANS Institute published "Beating the IPS". This report shows us different IPS evasion techniques manipulating the payload, header, and traffic flow of a well-known attack.

The target is evading detection by widely used products from major security vendors like Cisco, Check Point, Fortinet, Paloalto, TippingPoint and Snort trying to take advantage of MS08-067(http://technet.microsoft.com/en-us/security/bulletin/ms08-067), used by Conficker some years ago...




You can download the report by clicking on this link: http://www.sans.org/reading_room/whitepapers/intrusion/beating-ips_34137

The report's conclusion indicates the efficiency against the automatic attack, however, when we have a custom attack, the situation changes...

All vendors were bypassed using the default IPS settings except one: Checkpoint

The Sans's report recommends blocking Null sessions if we do not need them, and keep an eye on your IPS alerts.

Posted on Wednesday, April 03, 2013 by Javier Nieto

No comments