In our first blog on improving network security with what you already have, we examined some tips around logging for certain types of alerts as well as tips to detect bad guys in the network. But we saved the best for last: the IPS and firewall.

- One way of alerting on sensitive material, like merger and acquisitions info, is to look for keywords on the data itself. I’ve seen people hide certain phrases or words in documents while creating an IPS rule to search for these keywords. This isn’t a failsafe method, but it can help.
- Review the signatures on your IPS to make sure they’re reviewing protocols for exfiltration. A few of the protocols to review are DNS and SMTP, which will allow information leakage out of by adding or padding the protocols packets with additional information. This is a sneaky way to walk right past an IPS.
Read the rest of my article here: http://blog.algosec.com/2013/06/tips-to-improve-network-security-part-2-of-2.html
No comments:
Post a Comment