Technology Industry
Industry: Email Alert RSS FeedTippingPoint protects Cisco, Juniper infrastructure products in DoS attacks
Enterprise Networks & Servers, May 2005
TippingPoint, a 3Com Intrusion Prevention Systems (IPS) suite provided preemptive infrastructure protection for numerous Denial of Service (DoS) attacks affecting infrastructure products from Cisco and Juniper last month.
The DoS attacks last month would have allowed an attacker to reset or degrade an established Transmission Control Protocol (TCP) connection by spoofing Internet Control Message Protocol (ICMP) messages.
This could have implications for devices that require constant connections, such as routers that support BGP peering.
Without an IPS solution that offers immediate protection and works seamlessly with any vendor's networking equipment, enterprises must scramble to quickly deploy security patches for each individual product they use, and only when the vendor makes the patch available.
Most RecentTechnology Articles
DoS attacks typically result in a loss or degradation of network connectivity or services. Customers using TippingPoint's IPS are protected from the new infrastructure attacks and other DoS attacks, regardless of the equipment used in their network.
Infrastructure protection for these ICMP attacks was delivered to TippingPoint customers with a new batch of security filters addressing the recently announced Microsoft vulnerabilities and DoS infrastructure attacks.
For customers with TippingPoint network-based protection, vulnerable infrastructure products are protected by the TippingPoint IPS. TippingPoint also protects other technologies affected including Microsoft, IBM and Sun Microsystems.
"Intrusion prevention is an important component of protecting critical network infrastructure," said TippingPoint's Director of Digital Vaccine David Endler. "By design, most infrastructure products are not dynamically or automatically updated, and therefore, require IT personnel to manually implement individual patches on affected machines once they are finally made available by an equipment vendor and only during pre-defined IT maintenance windows. Intrusion prevention is part of the network infrastructure and is able to protect against attacks on routers and switches immediately, when placed in front of such products."
The DoS attacks were disclosed through the Internet Engineering Task Force (IETF) document entitled "ICMP Attacks Against TCP (watersprings.org/pub/id/draft-gonttcpm-icmp-attacks-03.txt)."
CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
Most Recent Technology Articles
- INTERVIEW WITH BEN BUTTERS, DIRECTOR OF EUROPEAN AFFAIRS AT EUROCHAMBRES : "A PERFECT ROAD MAP FOR EU CLUSTERS DOES NOT EXIST".
- AGENDA.(Brief article)(Conference notes)
- FIGHT AGAINST INTERNET PIRACY.
- INTERNET : AUTHORS' SOCIETIES URGE ACTION AGAINST PIRACY.
- TELECOMMUNICATIONS : BUSINESSEUROPE HOSTILE TO FURTHER CONTRACTUAL OBLIGATIONS.(Brief article)
Most Recent Technology Publications
Most Popular Technology Articles
- Speed control of separately excited DC motor
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Effects of creative, educational drama activities on developing oral skills in primary school children
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market
- Political stability and economic growth in Asia



