Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Hijak detection
From: Doy <doy @ indo-mail . com>
Date: Tue, 04 Nov 1997 21:33:13 +0700
To: "Firewalls @ GreatCircle . COM" <Firewalls @ GreatCircle . COM>

Guys, 

I wonder if there are firewall/intrusion detection products that can
deal with TCP session hijack.. I didn't see threads related to this
topic in the last half year ..okay, I'm new to this list.. ;)

Suppose the TCP session is not encrypted, and the attacker is on the
packet's route, what can we do about it? Surrender..??

Of course not. We can build statistical analysis on number of invalid
packets that transmitted on each session. Has anybody done this? Is this
approach valid anyway?

I'd like to see other solutions/products beside encryption/routing/netw.
segmentation.

regards,
Doy



Follow-Ups:
Indexed By Date Previous: Re: PPTP configuration
From: mfeinstein @ newoak . com (Michael G. Feinstein)
Next: Re: Linux et al PFs
From: "Jonathan M. Bresler" <jmb @ FRB . GOV>
Indexed By Thread Previous: Re: SSL WatchGuard
From: Eric Johnson <ej @ azid . com>
Next: Re: Hijak detection
From: Brad <brad @ freedom . gmsociety . org>

Google
 
Search Internet Search www.greatcircle.com