Re: IDS causing troubles

Curt Purdy <[email protected]> Fri, 18 Feb 2011 09:21:23 -0500
Newsgroups gmane.comp.security.ids
Message-ID <[email protected]>
If this were a literary list, we could argue semantics till the cows
come home Joel. But being an information security list let's stick to
technology. You may be too young to remember the very first Intrusion
'Protection' System that was not in-line at all. It was simply an IDS
that added ACLs to the firewall to block the grievous party. Everyone
accepted the developer's term 'IPS'.

Curt Purdy CISSP, GSNA, GSEC, MCSE+I, CCNA
[email protected]
[email protected]



On Tue, Feb 15, 2011 at 10:23 AM, Joel Esler <[email protected]> wrote:
> On Feb 11, 2011, at 2:14 PM, Joel Jaeggli wrote:
>
>> On 2/11/11 10:23 AM, Matthew Fitzgerald wrote:
>>> Joel, its inline because prevention requires intervention.
>>
>> It doesn't actually require that, plenty of ips systems can do their job
>> with a tap and another port for injection.
>
> I personally don't refer to that kind of a device as an IPS. =A0I refer t=
o that as a "reactionary IDS". =A0For instance, if the goal is to send a RS=
T packet back to the SRC IP that caused the IDS to alert, then the RST pack=
et has to beat the /actual/ ACK packet from the true DST IP back to the mac=
hine. =A0This is essentially, for lack of a better term, a "race". =A0This =
does not control traffic. =A0Plus, it gives away the hop location of your I=
DS within the network to the attacker. =A0I think if you are going to try a=
nd control traffic the much preferred method of doing so is an IPS. =A0Traf=
fic goes in one port, and it exits the other port. =A0While the traffic is =
inside the machine, the IPS makes the decision if the traffic should exist =
the other port, or it shouldn't. =A0That's a more controlling machine, thus=
ly an IPS.
>
>> the fact of the matter is if the ids can't keep up with the presented
>> load that's going to be a problem whether it's inline or presented
>> through a tap, in the later case however it's not going to cause an outa=
ge.
>
> True points there. =A0However, if you purchase an IPS that is correctly s=
pec'ed for your network (i.e. not putting a 1Gig IPS on a 2Gig link) you sh=
ould have little problem being able to handle the traffic. =A0It's mostly a=
 software/hardware problem.
>
> If you get a big enough box that is appropriately sized to handle the tra=
ffic, you should be able to perform the IPS function properly. =A0Although =
I've seen wide variances in this. =A0I've seen a 2Gig box do 4Gig/second of=
 traffic, and I've seen a 10Gig box do 2 Gig/second of traffic. =A0Test.
>
> --
> Joel Esler
> http://www.joelesler.net
>
>
> -----------------------------------------------------------------
> Securing Your Online Data Transfer with SSL.
> A guide to understanding SSL certificates, how they operate and their app=
lication. By making use of an SSL certificate on your web server, you can s=
ecurely collect sensitive information online, and increase business by givi=
ng your customers confidence that their transactions are safe.
> http://www.dinclinx.com/Redirect.aspx?36;5001;25;1371;0;1;946;9a80e04e1a1=
7f194
>
>
>

-----------------------------------------------------------------
Securing Your Online Data Transfer with SSL.
A guide to understanding SSL certificates, how they operate and their application. By making use of an SSL certificate on your web server, you can securely collect sensitive information online, and increase business by giving your customers confidence that their transactions are safe.
http://www.dinclinx.com/Redirect.aspx?36;5001;25;1371;0;1;946;9a80e04e1a17f194