Subscribe to RSS - Intrusion Detection And Prevention

Intrusion Detection And Prevention

Scientia Potentia Est (Knowledge is Power)

Submitted by Ofer Shezaf on 22 February 2012 - 10:36pm
Share/Save

The famous proverb “Knowledge is power” is attributed (probably wrongly) to Sir Francis Bacon, one of the founding fathers of the modern science. Usually referring to the contribution of science to the progress in human well-being in modern times, it is often criticized on the grounds that it takes action and not just knowledge to achieve progress.

The world of information security presents a similar dilemma. In my previous post, “black cat, white cat”, I divided the world of security controls into black listing tools for detecting and preventing attacks and whitelisting tools enforcing policies. However this is not the only categorization one can make of security tools: an orthogonal categorization would be between passive controls, the “knowledge”, and active controls, the “action”. Is knowledge power? Are passive controls which provide us with information but do not take an action effective?

A New Year, a New Acronym

Submitted by Ofer Shezaf on 9 January 2010 - 11:28pm
Share/Save

DragonSoft from Taiwan has introduced what they label a "Personal Web Application Firewall". The new product is essentially a low cost IIS plug-in and the "personal" label refers to the price rather than to some desktop protection. Since the press release itself mentions that the product is signature based, we at Xiom classify it as an IPS and not as a WAF in our product directory.

Detecting Credit Card Numbers in Network Traffic

Submitted by Ofer Shezaf on 10 December 2007 - 1:18am
Share/Save

1. Introduction