Talk With an Expert

Defending Against Code Red II Using Symantec NetProwler and Intruder Alert, ddos

Defending Against Code Red II Using Symantec NetProwler and Intruder Alert, ddos (PDF, 1.96MB)Published: 15 Aug, 2001
Created by:
Kenneth Donze

Today we are under attack from Code Red II. This worm has cost an estimated 2 billion dollars according to Computer Economics. Hotmail and FedEx have reported infections that cause shut down of some servers. Microsoft stated that at Hotmail no personal information was released, but how do they know? Did Microsoft use IDS, Intrusion Detection System, that tracked the activities that the worm performed? If they did use a IDS, why did they not catch the attack or the compromise of the WEB server? In this paper I will address the use of Symantec's NetProwler, network based IDS (NIDS), and Intruder Alert, host based IDS (HIDS), to detect and react to the Code Red II worm.