NTA Monitor

Latest News

Living with threats

1st August 2010 Back in 2004, Bill Gates predicted that spam would be a thing of the past within two years. As we all know now, and quite a lot of people predicted at the time, far from being a solved problem, the volume of spam has continued to increase. Read More

Web application security goes from bad to worse in many sectors

27th July 2010 NTA Monitor's 2010 Annual Web Application Security Report analysed the data gathered from web application security tests performed for a wide range of industry sectors over a 12-month period... Read More

IT Managers get to grips with Internet security issues

4th May 2010 According to NTA Monitor's 2010 Annual Security Report, the average number of Internet security vulnerabilities afflicting organisations has fallen.. Read More

Responsible Patching

1st January 2010 Microsoft's response to the "zero day" exploit that was used in the cyber attacks against Google shows that software vendors still have a lot to learn when it comes to responding to vulnerabilities. Read More

Firewall-1 Vendor ID Fingerprinting Glossary

Aggressive Mode One of the modes used by IKE in Phase-1 to establish an authenticated key exchange (the other mode is Main Mode).
Big Endian A byte ordering where the most significant byte is stored at the lowest address (first). This is the same as the "network byte order" used by TCP/IP.
Hybrid Authentication An IKE authentication method supported by Checkpoint Firewall-1 4.1 and later. Defined in draft-ietf-ipsec-isakmp-hybrid-auth-05.txt "A Hybrid Authentication Mode for IKE".
IKE Internet Key Exchange. The key exchange and authentication protocol used by IPsec. Defined in RFC 2409.
IPsec Internet Protocol Security. The IPsec protocol is used to create VPNs. It uses the IKE protocol for key exchange and authentication.
ISAKMP Internet Security Association and Key Management Protocol. ISAKMP provides the framework for key exchange and authentication that is used by IKE. ISAKMP is defined in RFC 2408.
Main Mode One of the modes used by IKE in Phase-1 (the first phase of the IKE packet exchange) to establish an authenticated key exchange (the other mode is Aggressive Mode).
NG Next Generation, the current major version of Checkpoint Firewall-1.
RSA Authentication An IKE authentication method using RSA public key encryption.
SA Security Association.
SHA1 Secure Hash Algorithm 1. A message digest (hash) function defined in RFC 3174.
Vendor ID An ISAKMP payload which contains a vendor-defined constant.
VPN Virtual Private Network.