Re: Ideal IDS/IPS
[email protected] 7 Jun 2011 13:45:29 -0000
| Newsgroups | gmane.comp.security.ids |
|---|---|
| Message-ID | <[email protected]> |
I'll take a stab!=0D =0D I would say there are two sorts of audiences for IDS/IPS: Those who care = and those who want it to run on its own with as little care and feeding a= s possible. For those that care, I'm not actually all that concerned abou= t false positives as I think a good analyst team should always go through= the manual tuning process themselves so they learn what their environmen= t feels like, but also determine for themselves the amount of noise they = want to see. Sometimes a rise or lull in noise is an indication of someth= ing strange.=0D =0D =0D Signature visibility - Essentially if there is an alert, I want to know d= efinitively why it triggered, whether a sig or statistics or whatever. I = don't want to ever guess.=0D =0D Traffic visibility - I don't want to call my IPS a full content capture t= ool, but I would like to see complete-enough traffic captures to match up= why an alert came up. As a bonus, it might be nice to manually trigger a= realtime capture just to see if a system is still spewing weird things o= r to possibily investigate a strange endpoint.=0D =0D in-line fail open - as much as possible anyway. Nothing gets an IPS furth= er behind in software than needing black-out windows for upgrades. Securi= ty via TCP resets is lame. Auto-changing device configs to implement bloc= ks is lame and doesn't scale with size or change. The "self-defending" ne= twork is scary.=0D =0D high degree of tuning ability - Some orgs only want to see clear attacks.= Some orgs have a real SOC and analysts who want to see as much as they c= an spend time seeing. Tuning should accomodate both sets, and be detailed= enough to ignore alert X that originates from system A to system B, but = still alerts on everything else.=0D =0D report on tuning/exceptions - Not much sucks more in an IPS than losing t= rack of what is tuned out. If an analyst makes a mistake and ignores half= your network, it would be nice to have any chance at all to see that mis= take if you regularly review your configs. A change like that in too many= commercial tools will be utterly lost forever. An emailed change report = on every change might help (and I'm not talking only a syslog entry you t= hen have to handle with other tools).=0D =0D clear, useful automated reporting - Customizable is fine.=0D =0D relatively free of bloat - A tool or feature that one customer requests a= nd thus gets put into the tool makes for bloat and confusion and being ov= erwhelmed for everyone else. This, to me, is the main failing of commerci= al security tools: So many features to appeal to every customer whim that= no single customer uses even 10% of the functionality. This results in a= lmost always being lost in the tool or feeling overwhelmed with what you'= re clearly not using. The same difference between a scalpel and a 100-too= l swiss knife.=0D =0D One wish-list item would be some pretty realtime graphs or dashboards or= something that show traffic patterns. I know there were some guys workin= g on a sniffing tool called Eve (white-dust guys who are no longer around= ) some time back, which had really pretty 3D visualizations for network t= raffic. I know I'm bending the point of an IPS into a netflow type of dev= ice, but sometimes an analyst's eyes will cross too much with 1000's of l= ines of alerts and logs. Sometimes, having a visual to look at not only g= ives managers warm fuzzies, but can offer new insight into strange things= .=0D =0D =0D =0D <- snip ->=0D =0D What would we like to have in an ideal IDS/IPS system? I am not=0D restricting the list to existing approaches such as signature based,=0D anomaly based, statistical or specification based IDS. Just trying to=0D get the wish list sort of. Any feedback is much appreciated.=0D =0D Low false negatives - maximize detection and prevention of=0D intrusions, detect zero day attacks, detect variations=0D Low false positives - don't waste analyst time=0D Ease of use - installation and configuration=0D Low resource usage - minimize resource usage, degrade gracefully=0D when resource usage exceeds limits=0D High Performance - good scalability with increasing network speeds=0D Stability, Robustness - no crashes, and resistance to attacks againt IDS=0D Minimal ongoing maintainence - Run with minimal human supervision=0D =0D Thanks=0D ----------------------------------------------------------------- Securing Your Online Data Transfer with SSL. A guide to understanding SSL certificates, how they operate and their app= lication. By making use of an SSL certificate on your web server, you can= securely collect sensitive information online, and increase business by = giving your customers confidence that their transactions are safe. http://www.dinclinx.com/Redirect.aspx?36;5001;25;1371;0;1;946;9a80e04e1a1= 7f194