PC USA's Intrusion Protection utilizes a database of over 2,000 rules to detect
patterns indicating : |
Hostile probing, port scans, backdoor probes, illegitimate
interrogations, host sweeps and other activities. |
Denial of service (DoS) attacks like SYN flood. |
Protocol exploitations, leveraging weaknesses in DNS, FTP, ICMP,
IMAP, POP3, SNMP, x11 and other network protocols. |
Application attacks, exploiting programming errors in internally
developed software and CGI scripts, and in popular applications. |
Targeted attacks that exploit the vulnerability of messaging and traffic
and Peer-2-Peer (p2p) networking. |
Hostile probing, port scans, backdoor probes, illegitimate
interrogations, host sweeps and other activities. |
Denial of service (DoS) attacks like SYN flood. |
Protocol exploitations, leveraging weaknesses in DNS,
FTP,ICMP,IMAP,POP3,RPC, SNMP,x11 and other network protocols. |
Application attacks, exploiting programming errors in internally
developed software and CGI scripts, and in popular applications and
databases such as Oracle, MySQL server, Coldfusion and Frontpage. |
Targeted attacks that exploit the vulnerability of messaging and chat
traffic and Peer-2-Peer (P2P) networking. |
| |
 |
PC USA performs intrusion detection by identifying suspicious behavior and
notifying the system administrator about incidents. The software can also
provide intrusion prevention by working with the firewall to immediately block
incoming traffic associated with instructions : |
Intrusion detection and prevention can be employed simultaneously. |
Threat Patterns are updated automatically. |
| |
 |
By putting intrusion protection in-line with the firewall, PC USA's Intrusion
Protection ensures that all Internet and VPN traffic is inspected, and that
there are no delays as traffic is routed to a separate sensor. PC USA can also
tailor testing to each network and server by: |
Enabling or disabling any of the over 1,500 rules. |
Customizing existing rules or creating new ones. |
Performing certain classes of tests only on specific networks or traffic
form specific servers (for example, executing email-related tests only
on traffic to and from email servers). |
| |
| Probes and attacks : |
Application and services : |
Protocols : |
| Backdoor Software |
Messaging and chat |
DNS |
| Denial of service |
MySQL Server database |
FTP |
| Distributed denial of service |
Oracle database |
ICMP |
| Network scanning |
CGI scripts |
IMAP |
| Unwanted traffic |
P2P networks (Napster, Kazaa) |
NetBIOS |
| |
Coldfusion |
NNTP |
| |
FrontPage |
P2P |
| |
Microsoft IIS |
POP2 |
| |
Multimedia streaming Software |
POP3 |
| |
|
RPC |
| |
|
SMTP |
| |
|
SQL |
| |
|
TFTP |
| |
|
X11 |
|
| |