MJ1
02-17-2003, 05:42 AM
I was reviewing Outpost Firewall and noticed some deficits that could be improved with plugins:
Is anyone interested in writing a plugin for DShield? You can learn more about DShield and obtain specs at http://www.dshield.org -- basically, the DShield network is an public-oriented early warning system. DShield captures firewall logs from network members to help determine what sort of attacks are happening around the Internet. For instance, DShield can help early detection of worms and trojans, etc. Membership in the network is open to anybody with a supported firewall. Unfortunately, Outpost is one of the few that are not supported, because nobody has written the software to obtain log info and transmit it to the DShield network. Anybody interested in writing such a plug in?
Also, is there any interest in somebody writing a more robust logging plugin in general for shield ? I notice that if I shutdown the firewall and and restart it, then the logs are wiped clean. There's no attack history to look at. Not that I can find anyway. Am I missing something? Or is there simply a lot of room for much better logging and log archiving?
Is anyone interested in writing a plugin for DShield? You can learn more about DShield and obtain specs at http://www.dshield.org -- basically, the DShield network is an public-oriented early warning system. DShield captures firewall logs from network members to help determine what sort of attacks are happening around the Internet. For instance, DShield can help early detection of worms and trojans, etc. Membership in the network is open to anybody with a supported firewall. Unfortunately, Outpost is one of the few that are not supported, because nobody has written the software to obtain log info and transmit it to the DShield network. Anybody interested in writing such a plug in?
Also, is there any interest in somebody writing a more robust logging plugin in general for shield ? I notice that if I shutdown the firewall and and restart it, then the logs are wiped clean. There's no attack history to look at. Not that I can find anyway. Am I missing something? Or is there simply a lot of room for much better logging and log archiving?