|
cirosec – Intrusion Prevention
Today, a number of completely different technologies go by the
name of Intrusion Prevention Systems.
These include classic network-based intrusion detection products,
which when an attack is detected automatically attempt to block
the attack, and inline filters, which detect attacks based on their
patterns and discard any dangerous packets, as well as Web application
filters, which are intended to prevent attacks at the application
level by analyzing all Web pages, forms, links and user input in
http transmissions.
Another area is host-based intrusion prevention systems, which
generally latch into the kernel of a server, where they prevent
attacks from successfully compromising the system.
State-of-the-art intrusion prevention systems often provide new
ways to solve security problems which cannot be dealt with viably
using conventional methods.
Solutions based on intrusion prevention are particularly suitable
for coping with the ever-increasing threat posed by worms.
We would be happy to advise you as to whether and in what areas
the use of intrusion prevention would be feasible to increase security
in your specific environment.
|