Re: Quarantine your infected users spreading malware

2006-02-23 Thread Jason Frisvold
On 2/23/06, Andy Davidson [EMAIL PROTECTED] wrote: And they don't care ! How is someone else telling them that they need a virus checker going to change anything ? It's not. That's why services such as AOL integrate it with the system.. Granted, the user has to initially accept it, but it's

Re: Quarantine your infected users spreading malware

2006-02-23 Thread Jack Bates
Andy Davidson wrote: And they don't care ! How is someone else telling them that they need a virus checker going to change anything ? We allowed users back online to run Housecall at trendmicro for free so they could get cleaned up and save some money. However, the resuspend rate was

Re: The Domain Name Service as an IDS

2006-02-23 Thread Mark Radabaugh
Amongst others, I've developed the following services with it for my internal customers: Hi Chris, thanks for your reply. I was just told by the admin team to keep DNS operational issues off-list. Would you mind if we take this to the DNS operations mailing list run by the ISC OARC?

Re: How do you (not how do I) calculate 95th percentile?

2006-02-23 Thread Daniel Roesen
On Wed, Feb 22, 2006 at 05:46:01PM -0500, Russell, David wrote: I personally think that 5 minute sampling is so last century s/5 minute sampling/polling/ RWSL[1] do deliver their accounting data via scp or FTP to collector hosts by themselves. Push instead of pull/poll. SNMP counter polling

Re: The Domain Name Service as an IDS

2006-02-23 Thread Joe Provo
On Thu, Feb 23, 2006 at 04:27:52AM +0200, Gadi Evron wrote: [snip] Hi Chris, thanks for your reply. I was just told by the admin team to keep DNS operational issues off-list. I deo not believe this. You didn't notice the Monday plenary session at NANOG 36 meeting was all DNS?

Re: Quarantine your infected users spreading malware

2006-02-23 Thread Eric Gauthier
Heya, Sorry about continuing this thread... I noticed a few people discussing this topic and wondering about new ways to look at quarantining hosts. There's a working group within the US Internet2 community that's been working on a generalized architecture and set of white-papers that our

Re: Quarantine your infected users spreading malware

2006-02-23 Thread Michael Loftis
--On February 23, 2006 8:02:31 AM -0600 Jack Bates [EMAIL PROTECTED] wrote: We allowed users back online to run Housecall at trendmicro for free so they could get cleaned up and save some money. However, the resuspend rate was so high, we quickly changed to offline cleanup only. It will

Re: a radical proposal (Re: protocols that don't meet the need...)

2006-02-23 Thread Iljitsch van Beijnum
On 16-feb-2006, at 0:15, Fred Baker wrote: On Feb 15, 2006, at 9:13 AM, Edward B. DREGER wrote: Of course not. Let SBC and Cox obtain a _joint_ ASN and _joint_ address space. Each provider announces the aggregate co-op space via the joint ASN as a downstream. Interesting. This is what

Re: Quarantine your infected users spreading malware

2006-02-23 Thread Gadi Evron
Michael Loftis wrote: What doesn't help is the ISPs out there who are complete dolts and first don't verify reports and second false alarm. They'll cut a user off on a single complaint without any evidence or verification. Or worse they have some automated system that false alarms without

Re: Quarantine your infected users spreading malware

2006-02-23 Thread Michael Loftis
--On February 23, 2006 9:09:26 PM +0200 Gadi Evron [EMAIL PROTECTED] wrote: I don't really see how any ISP will terminate an account for just one complaint, after all, it's losing money.. We have seen a few good examples of pretty big ISP's who said here how quarantine works for them. Got