IDS mailing list archives
RE: Recent Gartner IDS/IPS report
From: oherrera <oherrera () prodigy net mx>
Date: Wed, 18 Jun 2003 19:41:27 -0500
Aha!, we always come back to the trust dilemma, don't we? I think the same about this report from Gartner. Lets face it, we still don't trust enough our "old fashioned" IDS systems, even if we configure them to be completely passive. How are we going to trust more an IPS that is a lot more reactive and complex? I just can't imagine an IPS calling my ISP account manager to ask him to trace certain packets in order to confirm an attack before it blocks the suspicious, originating IP address. IPS is just a mix of different types of controls, they are not killing IDS, they are just integrating them better with other types of controls (filters for instance); sure there are advantages but we should treat the IPS hype with care: We should not forget about the swiss knife falacy (this won't solve all problems), we should not forget about single points of failure (1 box with many security features is still 1 box), mixing characteristics alos implies losing some advantages (there is no such thing as a passive IPS, there area passive and hard to detect IDS systems though). If we are not careful installing and configuring IPS systems, we will just give attackers more tools to allow them to DoS us. Trust is quite difficult with current network infrastructure and protocols where everything can be forged... (we still use IPv4 most of the time to comunicate, there are no reliable audit traces to feed even the perfect IPS). Just some thoughts, Omar Herrera
My 2 cents......until technology catches up (which I doubt it will be by 2005, despite what Gartner states) there is no single solution for IDS or IPS (or a firewall). We use a suite of tools that includes both and a firewall. In our environment we have been very successful in spotting new and old exploits, true, learning to identify an attack was costly (at first) but in the long run, well worth the expense (which includes periodic classes to maintain and learn new techniques). But consider the cost if we had not identified a compromised system and it continued to stay compromised because the firewall or an IPS did not identify it (real world example, had a compromise that made it through a firewall and IP tables). This whole argument (that Gartner started with an incomplete and not real world report) is like saying that human guards will be replaced by camera's, because it is cheaper to run a camera. Course someone has to look at the output from a camera, but who's counting. Camera's are good and guards are good, but together they make for tighter security. Point being...everyone knows how to have good physical security, because they can see it, however, when it comes to electronic security, because it can not be seen, it is harder to justify, harder to implement, etc., etc.. Steven T. Carey LCIRT-R Team Leader Comm (256) 876-5811 Cell (256) 947-0225
------------------------------------------------------------------------------- Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the world's premier technical IT security event! 10 tracks, 15 training sessions, 1,800 delegates from 30 nations including all of the top experts, from CSO's to "underground" security specialists. See for yourself what the buzz is about! Early-bird registration ends July 3. This event will sell out. www.blackhat.com -------------------------------------------------------------------------------
Current thread:
- Recent Gartner IDS/IPS report Gary Golomb (Jun 18)
- Re: Recent Gartner IDS/IPS report Stephen Samuel (Jun 18)
- Re: Recent Gartner IDS/IPS report Andreas Hess (Jun 22)
- Re: Recent Gartner IDS/IPS report Jeff Nathan (Jun 22)
- <Possible follow-ups>
- RE: Recent Gartner IDS/IPS report Carey, Steve T GARRISON (Jun 18)
- RE: Recent Gartner IDS/IPS report oherrera (Jun 19)
- RE: Recent Gartner IDS/IPS report Avi Chesla (Jun 19)
- RE: Recent Gartner IDS/IPS report Andre Yee (Jun 22)
- RE: Recent Gartner IDS/IPS report Golomb, Gary (Jun 22)
