Re: Ideal IDS/IPS

[email protected] 7 Jun 2011 13:45:29 -0000
Newsgroups gmane.comp.security.ids
Message-ID <[email protected]>
I'll take a stab!=0D
=0D
I would say there are two sorts of audiences for IDS/IPS: Those who care =
and those who want it to run on its own with as little care and feeding a=
s possible. For those that care, I'm not actually all that concerned abou=
t false positives as I think a good analyst team should always go through=
 the manual tuning process themselves so they learn what their environmen=
t feels like, but also determine for themselves the amount of noise they =
want to see. Sometimes a rise or lull in noise is an indication of someth=
ing strange.=0D
=0D
=0D
Signature visibility - Essentially if there is an alert, I want to know d=
efinitively why it triggered, whether a sig or statistics or whatever. I =
don't want to ever guess.=0D
=0D
Traffic visibility - I don't want to call my IPS a full content capture t=
ool, but I would like to see complete-enough traffic captures to match up=
 why an alert came up. As a bonus, it might be nice to manually trigger a=
 realtime capture just to see if a system is still spewing weird things o=
r to possibily investigate a strange endpoint.=0D
=0D
in-line fail open - as much as possible anyway. Nothing gets an IPS furth=
er behind in software than needing black-out windows for upgrades. Securi=
ty via TCP resets is lame. Auto-changing device configs to implement bloc=
ks is lame and doesn't scale with size or change. The "self-defending" ne=
twork is scary.=0D
=0D
high degree of tuning ability - Some orgs only want to see clear attacks.=
 Some orgs have a real SOC and analysts who want to see as much as they c=
an spend time seeing. Tuning should accomodate both sets, and be detailed=
 enough to ignore alert X that originates from system A to system B, but =
still alerts on everything else.=0D
=0D
report on tuning/exceptions - Not much sucks more in an IPS than losing t=
rack of what is tuned out. If an analyst makes a mistake and ignores half=
 your network, it would be nice to have any chance at all to see that mis=
take if you regularly review your configs. A change like that in too many=
 commercial tools will be utterly lost forever. An emailed change report =
on every change might help (and I'm not talking only a syslog entry you t=
hen have to handle with other tools).=0D
=0D
clear, useful automated reporting - Customizable is fine.=0D
=0D
relatively free of bloat - A tool or feature that one customer requests a=
nd thus gets put into the tool makes for bloat and confusion and being ov=
erwhelmed for everyone else. This, to me, is the main failing of commerci=
al security tools: So many features to appeal to every customer whim that=
 no single customer uses even 10% of the functionality. This results in a=
lmost always being lost in the tool or feeling overwhelmed with what you'=
re clearly not using. The same difference between a scalpel and a 100-too=
l swiss knife.=0D
=0D
One wish-list item would be some pretty  realtime graphs or dashboards or=
 something that show traffic patterns. I know there were some guys workin=
g on a sniffing tool called Eve (white-dust guys who are no longer around=
) some time back, which had really pretty 3D visualizations for network t=
raffic. I know I'm bending the point of an IPS into a netflow type of dev=
ice, but sometimes an analyst's eyes will cross too much with 1000's of l=
ines of alerts and logs. Sometimes, having a visual to look at not only g=
ives managers warm fuzzies, but can offer new insight into strange things=
.=0D
=0D
=0D
=0D
<- snip ->=0D
=0D
What would we like to have in an ideal IDS/IPS system? I am not=0D
restricting the list to existing approaches such as signature based,=0D
anomaly based, statistical or specification based IDS. Just trying to=0D
get the wish list sort of. Any feedback is much appreciated.=0D
=0D
Low false negatives - maximize detection and prevention of=0D
intrusions, detect zero day attacks, detect variations=0D
Low false positives - don't waste analyst time=0D
Ease of use - installation and configuration=0D
Low resource usage - minimize resource usage, degrade gracefully=0D
when resource usage exceeds limits=0D
High Performance - good scalability with increasing network speeds=0D
Stability, Robustness - no crashes, and resistance to attacks againt IDS=0D
Minimal ongoing maintainence - Run with minimal human supervision=0D
=0D
Thanks=0D

-----------------------------------------------------------------
Securing Your Online Data Transfer with SSL.
A guide to understanding SSL certificates, how they operate and their app=
lication. By making use of an SSL certificate on your web server, you can=
 securely collect sensitive information online, and increase business by =
giving your customers confidence that their transactions are safe.
http://www.dinclinx.com/Redirect.aspx?36;5001;25;1371;0;1;946;9a80e04e1a1=
7f194