IBM Computer, Laptops and Servers

Back Homepage Content Directory Resource Guide Blog

InterNiche Technologies Posts Fixes for TCP/IP Denial of Service Scenarios

InterNiche Technologies Posts Fixes for TCP/IP Denial of Service Scenarios

Updates to Firm's NicheStack TCP/IP Embedded Protocol

SAN JOSE, Calif.--(BUSINESS WIRE)--April 21, 2004--InterNiche Technologies, Inc., a major supplier of Internet and network security protocols stacks used worldwide by network devices and embedded applications OEMs, today announced that they have updated their NicheStack(TM) and NicheLite(TM) stacks to address the TCP Reset (RST) and SYN Attack vulnerabilities that were disclosed today by the United Kingdom's National Infrastructure and Security Coordination Centre. The use and effect of "spoofed" RST (Reset) and SYN packets on the TCP/IP Internet communications protocol was detailed today in NISCC Vulnerability Advisory #236929 and in a U.S. Department of Homeland Security alert. If exploited, these vulnerabilities could potentially allow a Denial of Service (DoS) attack on any TCP/IP session, forcing a premature termination. Any network service or application that relies on TCP/IP could be impacted.
"InterNiche has been working with the NISCC since first alerted to this vulnerability and on April 8th we informed NISCC that we had examined the scenario, had tested a patch and posted an updated version of our NicheStack IPv4, NicheStack IPv4/IPv6 Dual, and our NicheLite protocol stacks," said Brian Ramsey, Vice President of Marketing at InterNiche. "Embedded applications can be further protected with our IP Security (IPSec) toolkit, which encrypts information at the network layer completely obscuring the 4-tuple TCP address and port information."

Systems and services with persistent TCP/IP connections and relatively easy-to-guess address and port numbers are the most vulnerable targets for this form of DoS, or a Distributed DoS attack if launched from multiple cooperating machines. Border Gateway Protocol (BGP) routers, Domain Name Servers (DNS) and well-know e-commerce sites were identified as potentially affected by this vulnerability.

Availability

InterNiche Technologies has updated its NicheStack v2.0 and NicheLite v2.0 TCP/IP protocol stack products to handle the scenarios described in NISCC Vulnerability Notice #236929. The patch is available to all InterNiche customers in accordance with the terms of their current support agreements.

About InterNiche

InterNiche Technologies has been developing and licensing networking management and configuration software for embedded systems since 1989. Hundreds of thousands of products depend on InterNiche software as part of their core functionality. Customers include companies such as 3COM, Ericsson, Intel, Hewlett Packard, Nortel Networks, Raytheon, Samsung, Siemens, and many more. For more information please contact sales@iniche.com or visit InterNiche on the web at www.iniche.com.

Contacts


InterNiche Technologies, Inc.
Brian Ramsey, 408-257-8014
bramsey@iniche.com

[ Comment, Edit or Article Submission ]

Share this:

Add To Yahoo MyWeb Add To Google Bookmarks Add To Furl Fav This With Technorati Add To Newsvine Add To Bloglines Add To Ask Add To Windows Live Add To Slashdot Stumble This Digg This Add To Del.icio.us Add To Reddit

More about:

Nov December 2008 Jan
Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      

IBM Computer, Laptops and Servers Blog on Technorati Related Blog of IBM Computer, Laptops and Servers on Sphere
Content Directory
Resource Guide


EDGE Tech Corporation

Website Links
IBM Computer, Laptops and Servers Copyright © 2008 www.ibmfans.com. All rights reserved. Site Map
Homepage | Blog | Advertise | Privacy Policy | Disclaimer | Contact Us | Links