IDS mailing list archives

RE: Recent Gartner IDS/IPS report


From: oherrera <oherrera () prodigy net mx>
Date: Wed, 18 Jun 2003 19:41:27 -0500

Aha!, we always come back to the trust dilemma, don't we?
I think the same about this report from Gartner.

Lets face it, we still don't trust enough our "old
fashioned" IDS systems, even if we configure them to be
completely passive. How are we going to trust more an IPS
that is a lot more reactive and complex?

I just can't imagine an IPS calling my ISP account manager
to ask him to trace certain packets in order to confirm an
attack before it blocks the suspicious, originating IP
address.

IPS is just a mix of different types of controls, they are
not killing IDS, they are just integrating them better with
other types of controls (filters for instance); sure there
are advantages but we should treat the IPS hype with care:

We should not forget about the swiss knife falacy (this
won't solve all problems), we should not forget about single
points of failure (1 box with many security features is
still 1 box), mixing characteristics alos implies losing
some advantages (there is no such thing as a passive IPS,
there area passive and hard to detect IDS systems though).

If we are not careful installing and configuring IPS
systems, we will just give attackers more tools to allow
them to DoS us. Trust is quite difficult with current
network infrastructure and protocols where everything can be
forged... (we still use IPv4 most of the time to comunicate,
there are no reliable audit traces to feed even the perfect
IPS).

Just some thoughts,

Omar Herrera

My 2 cents......until technology catches up (which I doubt
it will be by 2005, despite what Gartner states) there is
no single solution for IDS or IPS (or a firewall).  We use
a suite of tools that includes both and a firewall.  In
our environment we have been very successful in spotting
new and old exploits, true, learning to identify an attack
was costly (at first) but in the long run, well worth the
expense (which includes periodic classes to maintain and
learn new techniques).  But consider the cost if we had
not identified a compromised system and it continued to
stay compromised because the firewall or an IPS did not
identify it (real world example, had a compromise that
made it through a firewall and IP tables).

This whole argument (that Gartner started with an
incomplete and not real world report) is like saying that
human guards will be replaced by camera's, because it is
cheaper to run a camera.  Course someone has to look at
the output from a camera, but who's counting.  Camera's
are good and guards are good, but together they make for
tighter security.
Point being...everyone knows how to have good physical
security, because they can see it, however, when it comes
to electronic security, because it can not be seen, it is
harder to justify, harder to implement, etc., etc..
Steven T. Carey
LCIRT-R Team Leader
Comm (256) 876-5811
Cell (256) 947-0225

-------------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
world's premier technical IT security event! 10 tracks, 15 training sessions, 
1,800 delegates from 30 nations including all of the top experts, from CSO's to 
"underground" security specialists.  See for yourself what the buzz is about!  
Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
-------------------------------------------------------------------------------


Current thread: