Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Feb 2004 13:13:25 +1100 (Australia/ACT)
From:      Darren Reed <avalon@caligula.anu.edu.au>
To:        bj93542@yahoo.com (Dorin H)
Cc:        freebsd-security@freebsd.org
Subject:   Re: traffic normalizer for ipfw?
Message-ID:  <200402200213.i1K2DPoC021725@caligula.anu.edu.au>
In-Reply-To: <20040220003052.41695.qmail@web12606.mail.yahoo.com> from "Dorin H" at Feb 19, 2004 04:30:52 PM

next in thread | previous in thread | raw e-mail | index | archive | help
In some mail from Dorin H, sie said:
> 
> True, it's part of IDS. Nevertheless, do you think
> that traffic normalizing is useful?

No.

The worst part of normalizing traffic is that it "tampers"
with your evidence that comes in from the network.

Darren



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200402200213.i1K2DPoC021725>