Re: Can Zeek be installed as in-line IPS?
James Lay <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <[email protected]> |
On 2019-03-18 11:02, Seth Hall wrote: > On 18 Mar 2019, at 11:30, Patrick Kelley wrote: > >> I still see the same issues we had on networks 10 years ago. It is >> reduced, due to HTTPS and some SMTP, sure. Dead... not really. > > To be fair, he did say IPS. In my opinion IPS has always been in a > weird spot where the definition isn't terribly clear (block a single > packet in-flight? block a connection after a determination is made? > ...etc). > > I think everyone here will agree that the visibility provided by Zeek > is > useful even on modern networks and that tail of completely unencrypted > traffic is awfully long. :) > > .Seth > > -- > Seth Hall * Corelight, Inc * www.corelight.com > _______________________________________________ > Zeek mailing list > [email protected] > http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek Concur. Zeek on the perimeter is great for metadata about encrypted sessions. Zeek internally from client/server or Windows Client/Windows Domain Controller will open your eyes to a LOT of traffic you may not have expected. James _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek