Re: a cutting-edge open-source network security project
[email protected] Fri, 7 May 2010 15:31:12 -0700
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
On Wed, May 05, 2010 at 11:39:40PM -0500, Frank Knobbe wrote: > On Sun, 2010-05-02 at 15:48 -0700, [email protected] > wrote: > > [...] Another idea is to "federate" against attacks, so that when your IDS > > (say, snort) detects an attack from an external entity, you block that > > entity at multiple locations (each of which run DFD, but which may run > > entirely different OSes and firewalls). This hasn't been implemented > > but could prove itself rapidly useful (if engineered carefully). > > When you say "this hasn't been implemented", are you referring to DFD? Well, yes, I mean I haven't implemented a distributed blocking fabric with DFD. > I'm just asking because this approach has been around for a while. > Snortsam is now nearly a decade old and uses the approach of you call > "federated" defense, which I call "distributed blocking fabric". > (Snortsam receives block requests from one or more Snort instances and > blocks on one of more firewalls, or forwards the request to other > Snortsam instances). And I can attest that this approach works extremely > well (detect once, protect many). I see. I had heard the name snortsam and looking at it, it seems to have similar goals. One might characterize these in two ways: snortsam can block IPs on multiple firewalls DFD can implement any rule changes on any firewall > Snortsam as it stands just works :) and 2) we're enumerating so many > hostile IP's (even if only blocked for periods of time) that traditional > firewalls can no longer handle the load. Yeah, I discuss some other options in the DFD paper: http://www.subspacefield.org/security/dfd/#tth_sEc7 You'll note I've also linked to snortsam as related work. > Which led me to the development > of a new firewall module that, coupled with a database driven management > framework, can now handle transient shunning of millions of IP > addresses. I almost completed my migration from Snortsam to the new > framework. Interesting. What firewall is it for? iptables? Pf has something called tables that are supposed to be relatively dense IP sets. Not sure if it would scale to your site's size though; just a possibility. > Anyway, it looks like your DFD has a couple interesting features (for > example, the dynamic NAT stuff). One thing I'd like to do is design a secure protocol for telling the NAT device to do port forwarding, so that when an app fires up it can securely send a structured file that does port forwarding. I ran into this when trying to play Civ IV online behind a strict firewall; I had to google for port numbers and so on, and never finished testing to make sure I had it right. Very user-unfriendly. -- A Weapon of Mass Construction My emails do not have attachments; it's a digital signature that your mail program doesn't understand. | http://www.subspacefield.org/~travis/ If you are a spammer, please email [email protected] to get blacklisted. _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (OpenBSD) iQIcBAEBAgAGBQJL5JSvAAoJEGQVZZEDJt9HZWEP/2Q3BQvUeIbrRE06roARTvXB 6YEC+csj41uX5SKAe8akH7JbQstjuR0Z8cMzBVQkIMnG7f1ehEFxA53RBVvOyN8W 1cpeUvaSAQXJoT0pUTL+fcce5C/VK7cFx8F4Ss0PYJ0762XmFZtDMqaDodI+S62q DeSNHxD0tkmHPV3c8gkOa6oPU90v4GaQ6eA7U9z9UNvvnF7XdA1BdyLq/68rHDTS MDPzk0JBMmxsYdHcoA4AKgekUGRDOmcbGGHM9cia78utYSaTnMD+IJ+h9N8MWERR a+w9BrnGhFjA0vqwrcTZgS8OPwYAJHKb7iZExtVLK4wuo4x4XeFZcmZ7W939eqPj 8mT4Eza0qtEC7os0g3ZQrdY/1AupU1Gzkt+k0iNJIVsO8URYKnou532MwYnJOdfR wGTaOIcd23Vsh3Qy8syZYnF6CsAn9LhbAEuQdESwq12DjUHqH1UOm6OEvFqJG+zK vGFLh4WIkR3e+Wjne4zHfqADlTy4IMsmC1e2Crp+FUhLXEJFMkF+Hw5/ylOoCeZZ DXk0vbmBACplKLJbrYnNXV0ilQtyNynnuFCqqkKUDRyCQAsrLBB41dFlQ8DZ1V1D TSrDo40pYnvPEGbBeuZ/KaB3fji2VOwmyDf+LuAX6sS8pE3eWHZcIVBvc0+y+QS/ u5loKfhI1RSDLdaOu68O =38I6 -----END PGP SIGNATURE-----