Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



IDS: Preventing layer 3/4 evasions

Preventing layer 3/4 evasions

From: Steve Reinhardt <stever_at_reservoir.com>
Date: Wed, 19 Dec 2007 17:14:33 -0800

I'm curious about the market status quo and trends in the area of how
network IDS/IPS products are dealing with layer 3/4 evasion techniques
(a la Ptacek & Newsham: ambiguous segmentation & fragmentation, ttl
tricks, etc.). The Handley/Paxson/Kreibich paper from Usenix01 lists
three approaches (not counting "use a host-based IDS" :-) ):
1. inline normalization
2. profiling the intranet and using target-specific algorithms
3. bifurcating analysis

 From what I've read, Snort is going route #2, with the Sourcefire RNA
system doing the profiling.

- Is there any public information regarding which approach (if any)
other commercial systems are using?

- Does Snort's decision indicate any sort of consensus that #2 is the
best approach, or would that be considered controversial? (Clearly #3
isn't practical as a general technique, but the Handley paper seems to
make a good case for #1.)

- Do you all feel that existing approaches (like Snort's, or perhaps
some commercial implementation of #1) are adequate, or is there a need
for a more robust solution?

Basically we've had some ideas in this space and are trying to figure
out whether they're worth pursuing... guess I should add "If so, how
much would you pay for it?" to the last question :-).

Thanks!

Steve

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------
Received on Dec 20 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]