Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
I've read IDS/IPS is useless because nowadays all malware/hacker traffic is encrypted anyways. Is this true?If you have an old pc, you can add a $10 network card (total of 2 nic's), and install the pfSense firewall. Then install the included add-on snort IPS. Then subscribe to the free snort community rules and free emergingThreats rules.
There you have it, free hardware firewall.
There is a thing called SSL Decryptor. This decrypt and reencrypt traffic after inspection for IDPS purposes.I've read IDS/IPS is useless because nowadays all malware/hacker traffic is encrypted anyways. Is this true?
The claim that Intrusion Detection/Prevention Systems (IDS/IPS) are useless because all modern traffic is encrypted is a significant oversimplification. While it's true that widespread encryption, such as TLS/SSL, creates a "blind spot" for traditional systems, it hasn't rendered them obsolete. These systems have evolved and remain a crucial part of a robust cybersecurity strategy. Modern IDS/IPS can still analyze unencrypted metadata to identify threats. For instance, they inspect source and destination IP addresses and ports, which allows them to block traffic to known malicious IPs. They also monitor traffic volume and timing, with unusual spikes or communication patterns often serving as red flags. Additionally, by analyzing TCP/IP header information, they can detect low-level network attacks like port scans and SYN floods. Furthermore, these systems have adapted in other ways, including the use of behavioral analysis and machine learning to identify anomalous traffic patterns even when payloads are encrypted. Some organizations even deploy SSL/TLS inspection, where the IDS/IPS decrypts, inspects, and then re-encrypts the traffic to gain full visibility. Finally, host-based IDS/IPS (HIDS/HIPS) systems are installed directly on endpoints, giving them a clear view of data before and after encryption, thereby bypassing the network encryption problem entirely. In short, while encrypted traffic presents a challenge, IDS/IPS have adapted and continue to be an effective layer in a comprehensive "defense-in-depth" security model.I've read IDS/IPS is useless because nowadays all malware/hacker traffic is encrypted anyways. Is this true?
Members who viewed this thread in the last 5 minutes