IDS mailing list archives

RE: Recent Gartner IDS/IPS report


From: "Golomb, Gary" <GGolomb () enterasys com>
Date: Thu, 19 Jun 2003 15:45:22 -0400


See source domain... Vendor alert! As with most of the stuff that comes
out of my mouth - my views and opinions, not that of my employer. 

This is the last one from me, and I'm going quiet again...


I agree with Gartner's statement, that the next generation of security
products will integrate automatic prevention capabilities into their
systems. This is already happening (IPS - Intrusion Prevention
Systems)
and
my opinion is that this reflects the market's needs currently and in
the
future.

Why is that?

The increasing value of the Internet have raised the demands for
faster
security solutions and, most importantly, automatic active devices
that
can
provide proper countermeasures to the attacks.  Due to the speed and
frequency of attack methods, these devices must also be able to
execute
defensive actions without human intervention in minimum time. The
majority
of Internet connected organizations do not have the necessary time or
resources to properly analyze security reports, implement necessary
countermeasures and execute them.   If the organization's Internet
infrastructure and applications aren't easily accessible or are
difficult
to
use, the customers who expect to get fast and reliable online services
will
simply find another available service (usually from a competing
organization).
Human decisions and actions take time and, in a world dominated by
fast
hardware and communication lines, some of the decisions and
countermeasures
will have to be done automatically by the security devices in order to
avoid
losing customers.



While attacks affecting a carrier/service-provider are definitely
relevant, do not confuse the issue of dealing with those threats with
the vastly different hazards faced by content providers, enterprises,
governments, etc. They all have significantly different exposures and
weaknesses, so they have different challenges to be faced with. You're
making a marketing statement for why you agree with Gartner based on a
small piece of the full puzzle. This actually raises a point that hasn't
been directly made yet... (Highlighted below.)


It is not clear however, what Gartner means by saying that firewalls
(with
more security functionalities - network and applications protections)
will
replace the IDS products. Intrusion analysis is an entirely different
technology than the technology which is associated with current
firewalls
products. Integrating both technologies in the same product is
possible
and
it seems that this is what Gartner was intending to explain,
unsuccessfully.


The fact that we're even having a discussion trying to figure out what
Richard meant in his paper is a problem. If Gartner publishes papers
with titles like, "IDS is Dead, Long Live IPS," then they better be able
to articulate why they're saying it. (Hrmmm... Let me guess... My bet is
on one of the authors having a book coming out soon. Any takers? I just
bought a Mega Millions lotto ticket, so I'll bet big.)  



Although it might upset some vendors, if automatic prevention is what
the
market wants, it is a fact that the current IDS products which are
associated with an excessive amount of false positives, will not be
able
to
provide.


You might want to search the list archives for technical talk about
false positives. Of course, since these same vendors compete with your
product, I understand your stance. Its funny how conversations about
false positives from vendors always avoid [like the plague] *technical*
discussions about false negatives. Actually, I take that back - it's not
funny at all. 

By the way, that's kind of the point of the BACKEND components to the
front-end pieces people like to complain about. Sure there's room for
improvement on the backend too, but vendors and working on that also.
However, at least filtering false positives based on "data management
improvements" (read: backend) versus "sensor modifications" (read:
front-end - as you're proposing) doesn't cut out that other important
piece of the puzzle - audit trail and forensic evidence[1]. Sometimes it
takes days/weeks/months to determine if something is a false positive or
not. Sure is nice to have that data available when you find out it's
not. 

Ok, so I'll bite... I'll agree that the paper was correct. In very
specific scenarios. The market as a whole? Are you kidding?!?! 

Basing IPS entirely on IDS and making the offspring a single product is
also the correct answer - in some scenarios. 

Basing IPS solely on Firewalls is a correct answer too - in other
scenarios. 

Basing IPS on application proxy/firewalls is good too - in further
scenarios.

The point is, each has its pros/cons. You don't have to look very far
for a good analogy. Look at the current state of IDS. You have
methodologies such as pattern matching which are excellent at finding
very specific and acute signs of attacks or compromise. You can generate
much more information about specific events from this technique over all
others (protocol decoding, anomaly, etc). On the opposite end of the
spectrum, you have anomaly-based technologies which are great at finding
the types of deviations other systems would never see, at the expense of
detailed event information or reporting capabilities. Which is better?
Depends. What do you care about? What do you want from a system? And
what do you want to do with the information after you have it?

To say the market as a whole wants one capability over another (as you,
in addition to Gartner, have done) is foolhardy and misleading. IPS
purpose-built around solving all the problems of a firewall (rules
implemented on application protocols beyond port numbers and moving
state tracking beyond the TCP layer) makes sense from an engineering and
enterprise implementation standpoint. Notice I didn't say ignore
lessons-learned from the IDS space. You still need to learn from those
techniques of exploit and vulnerability analysis, but you don't have the
same number of points in your data set to make pass/no-pass decisions.
You really need to change your way of thinking at the very beginning of
the analysis process from the IDS-centric model of "suspicious or not
suspicious" to "allowed or not allowed." That sounds easy on the
surface, but not so much when you get hands-into exploit and
vulnerability analysis.

Then there's the argument (and current direction of the industry which
Gartner/Richard has based their claims on) that takes the approach of
basing IPS on existing IDSs. That is, taking an IDS, moving it to be
in-band (versus out-of-band) and integrating firewall-like behavior into
it. This is a perfectly acceptable solution for stopping some blatant
types of attacks. Lot of the possible alerts and IDS can generate are
definitely bad activities, but many more of them are more ambiguous - no
matter what kind of detection methodologies you rely on. Sure you can
stop those blatant ones, but what about all the rest? Don't kid
yourself. This will not and cannot stop all attacks. Is it good enough
though? Depends what kind of attacks you're most concerned about. These
devices will do nothing for the advanced analysis required to find
attacks against custom applications that application proxies have the
potential to find.

Why not get (or make) a box that does it all? Simple: computing
resources. (ASIC, Network Processor, or otherwise!)  If you could
combine FULL IDS, FULLY stateful firewalling, FULL RFC protocol
enforcement, FULL anomaly detection, FULL protocol decoding, FULL binary
traffic analysis, etc. on one box... Well, it wouldn't be a security
device, it'd be an end-station and you wouldn't need security devices
anymore.  

To say IPS based on IDS -or- firewall -or- application proxy -or- etc.
is a better technique without defining exactly what its better compared
to, why,  AND what it's WORSE at is irresponsible and ignorant. To say
IPS based on ANYTHING will fully replace the auditing/forensic/policy
monitoring/etc. capabilities allowed by IDS is even worse - no matter
how you try to justify it. Made-up market demands or otherwise. Don't
think those market demands are made up??? How do you explain:

"Ranum): In private communications with Stiennon (the Gartner analyst),
he offered the shocking fact that - for all that they are hyping IPS -
the team at Gartner 'doesn't know anyone who is using an IPS in inline
mode.'  That runs utterly contrary to the perception they are trying to
create that IPS is the 'wave of the future'"

Anyways, the best solution for one environment is not going to be a
market-wide best solution. I'm glad there are several other vendors who
haven't completely succumbed to money-making hype and are taking a more
responsible approach to researching these technologies. It's nice to
see, and I applaud them all. 

Feeling like he's beating a horse that's already one step away from
glue,

-Gary


[1]Forensic evidence from an IDS does not need to be used for
prosecution to be useful. It's also good for general incident response
and containment, policy enhancements, trending/tracking, admin/developer
training, research, etc... 






































-------------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
world's premier technical IT security event! 10 tracks, 15 training sessions,
1,800 delegates from 30 nations including all of the top experts, from CSO's to
"underground" security specialists.  See for yourself what the buzz is about!
Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
-------------------------------------------------------------------------------


Current thread: