Re: Anti-spyware at the Gateway
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Anti-spyware at the Gateway

From: Volker Birk <bumens@dingens.org>
Date: Mon Mar 13 2006 - 17:05:21 CET

Somebody. <somebody.@nospam.russdoucet.com> wrote:
> > You cannot detect arberaty tunneling techniques.
> Not easily. But you can.

For this problem is equivalent to the halting problem, you cannot in
every case. There is no algorithm which can.

> They each have some sort of behavior that is not
> like their neighbors on the network. You simply have to notice it. Noticing
> things that are outside of the normal is a start, when you turn your full
> attention to it, you will figure it out.

Of course, you can detect it if you're lucky. And it will help very
much, if the person, who is implementing the tunneling, is dumb.

If the tunneling is done in a clever way, it will be very hard up to
impossible to detect. Of course, this depends on how much data usually
is transmitted regulary, and how much information is to be transmitted
hidden.

Yours,
VB.

-- 
Wenn Du "Ich sehe die Mathematik als einzigen Bereich an, wo es klare
Beweise gibt." und "Ich fuehle mich in einem Anzug unwohl." als Aussagen
mit aequivalentem Meinungsinhalt betrachtest, hast Du mit Deinem Gleichnis
recht. (Michail Bachmann zu Thomas Wallutis in d.a.s.r)
Received on Mon May 1 00:56:47 2006