<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zero-day attacks through a SIG in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544763#M92737</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think as long as the "zero day" attack uses a vulnerability with a sig it should.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An example is a "new" way to exploit ASN.1.  This new exploit should cause the ASN.1 vulnerability signature to fire on the IDS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However a true zero-day attack (an unknown vulnerability with exploit code to take advantage of it) would probably get through unnoticed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the opinion of Cisco as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Aug 2006 17:48:46 GMT</pubDate>
    <dc:creator>DFiore</dc:creator>
    <dc:date>2006-08-02T17:48:46Z</dc:date>
    <item>
      <title>Zero-day attacks through a SIG</title>
      <link>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544762#M92734</link>
      <description>&lt;P&gt;Can the IDS catch zero-day attacks and report on them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544762#M92734</guid>
      <dc:creator>jlwomeld</dc:creator>
      <dc:date>2019-03-10T10:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Zero-day attacks through a SIG</title>
      <link>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544763#M92737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think as long as the "zero day" attack uses a vulnerability with a sig it should.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An example is a "new" way to exploit ASN.1.  This new exploit should cause the ASN.1 vulnerability signature to fire on the IDS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However a true zero-day attack (an unknown vulnerability with exploit code to take advantage of it) would probably get through unnoticed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the opinion of Cisco as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 17:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544763#M92737</guid>
      <dc:creator>DFiore</dc:creator>
      <dc:date>2006-08-02T17:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Zero-day attacks through a SIG</title>
      <link>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544764#M92739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By definition, a "zero-day" attack is one that is unknown and does not have a signature, yet. That is where a behavior-based IDS comes in handy instead of signature-based one. It should provide additional protection for zero-day attacks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are looking for a Cisco product in this realm, you should look at Cisco Security Agent (a Host-based IDS that looks at behavior, not signatures).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 20:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544764#M92739</guid>
      <dc:creator>wyley.johnson</dc:creator>
      <dc:date>2006-08-02T20:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Zero-day attacks through a SIG</title>
      <link>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544765#M92741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is my take on this subject.  Security should be installed in layers.  From hte Perimeter to the core and then on end points and network nodes.  You should have properly hardened routers backed up by a firewall with IDS/IPS on the outside and inside.  Then a properly segmented network by way of VLANS etc to allow traffic only where it needs to go.  Should anyone get past these measures then host-based intrusion prevention by products such as Cisco Security agent will come into play for "zero-day" attacks.  CSA works off rules, not patterns so the end result is if the "zero-day" attack tries to do something it is not allowed to do, write to the registry, delete files, etc, CSA kicks in to stop it.  No signatures needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Learn more about this and other fine Cisco products at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/index.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now go ask John Cambers if my endorsement check is ready. I have a car note due.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to rate all replies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 20:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544765#M92741</guid>
      <dc:creator>travis-dennis_2</dc:creator>
      <dc:date>2006-08-02T20:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Zero-day attacks through a SIG</title>
      <link>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544766#M92743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just thought I would thow this into the conversation.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;The Cisco Anomaly Guard and Anomaly Detector products are designed to look for and protect from Anomalous traffic on the network.  The Anomalous traffic can often be caused by "zero-day" attacks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an Ask The Expert event that started on July 28th and will last until August 11th that is specifically discussing the Guard and Detector.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddbc7d1" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddbc7d1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you want to learn more about how Guard and Detector can help in protecting against "zero-day" attacks you might try posting a comment on the Ask the Expert postings.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 22:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zero-day-attacks-through-a-sig/m-p/544766#M92743</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2006-08-02T22:16:42Z</dc:date>
    </item>
  </channel>
</rss>

