IDS mailing list archives
RE: Recent Gartner IDS/IPS report
From: "Golomb, Gary" <GGolomb () enterasys com>
Date: Thu, 19 Jun 2003 15:45:22 -0400
See source domain... Vendor alert! As with most of the stuff that comes out of my mouth - my views and opinions, not that of my employer. This is the last one from me, and I'm going quiet again...
I agree with Gartner's statement, that the next generation of security products will integrate automatic prevention capabilities into their systems. This is already happening (IPS - Intrusion Prevention
Systems)
and my opinion is that this reflects the market's needs currently and in
the
future. Why is that? The increasing value of the Internet have raised the demands for
faster
security solutions and, most importantly, automatic active devices
that
can provide proper countermeasures to the attacks. Due to the speed and frequency of attack methods, these devices must also be able to
execute
defensive actions without human intervention in minimum time. The
majority
of Internet connected organizations do not have the necessary time or resources to properly analyze security reports, implement necessary countermeasures and execute them. If the organization's Internet infrastructure and applications aren't easily accessible or are
difficult
to use, the customers who expect to get fast and reliable online services will simply find another available service (usually from a competing organization). Human decisions and actions take time and, in a world dominated by
fast
hardware and communication lines, some of the decisions and countermeasures will have to be done automatically by the security devices in order to avoid losing customers.
While attacks affecting a carrier/service-provider are definitely relevant, do not confuse the issue of dealing with those threats with the vastly different hazards faced by content providers, enterprises, governments, etc. They all have significantly different exposures and weaknesses, so they have different challenges to be faced with. You're making a marketing statement for why you agree with Gartner based on a small piece of the full puzzle. This actually raises a point that hasn't been directly made yet... (Highlighted below.)
It is not clear however, what Gartner means by saying that firewalls
(with
more security functionalities - network and applications protections)
will
replace the IDS products. Intrusion analysis is an entirely different technology than the technology which is associated with current
firewalls
products. Integrating both technologies in the same product is
possible
and it seems that this is what Gartner was intending to explain, unsuccessfully.
The fact that we're even having a discussion trying to figure out what Richard meant in his paper is a problem. If Gartner publishes papers with titles like, "IDS is Dead, Long Live IPS," then they better be able to articulate why they're saying it. (Hrmmm... Let me guess... My bet is on one of the authors having a book coming out soon. Any takers? I just bought a Mega Millions lotto ticket, so I'll bet big.)
Although it might upset some vendors, if automatic prevention is what
the
market wants, it is a fact that the current IDS products which are associated with an excessive amount of false positives, will not be
able
to provide.
You might want to search the list archives for technical talk about false positives. Of course, since these same vendors compete with your product, I understand your stance. Its funny how conversations about false positives from vendors always avoid [like the plague] *technical* discussions about false negatives. Actually, I take that back - it's not funny at all. By the way, that's kind of the point of the BACKEND components to the front-end pieces people like to complain about. Sure there's room for improvement on the backend too, but vendors and working on that also. However, at least filtering false positives based on "data management improvements" (read: backend) versus "sensor modifications" (read: front-end - as you're proposing) doesn't cut out that other important piece of the puzzle - audit trail and forensic evidence[1]. Sometimes it takes days/weeks/months to determine if something is a false positive or not. Sure is nice to have that data available when you find out it's not. Ok, so I'll bite... I'll agree that the paper was correct. In very specific scenarios. The market as a whole? Are you kidding?!?! Basing IPS entirely on IDS and making the offspring a single product is also the correct answer - in some scenarios. Basing IPS solely on Firewalls is a correct answer too - in other scenarios. Basing IPS on application proxy/firewalls is good too - in further scenarios. The point is, each has its pros/cons. You don't have to look very far for a good analogy. Look at the current state of IDS. You have methodologies such as pattern matching which are excellent at finding very specific and acute signs of attacks or compromise. You can generate much more information about specific events from this technique over all others (protocol decoding, anomaly, etc). On the opposite end of the spectrum, you have anomaly-based technologies which are great at finding the types of deviations other systems would never see, at the expense of detailed event information or reporting capabilities. Which is better? Depends. What do you care about? What do you want from a system? And what do you want to do with the information after you have it? To say the market as a whole wants one capability over another (as you, in addition to Gartner, have done) is foolhardy and misleading. IPS purpose-built around solving all the problems of a firewall (rules implemented on application protocols beyond port numbers and moving state tracking beyond the TCP layer) makes sense from an engineering and enterprise implementation standpoint. Notice I didn't say ignore lessons-learned from the IDS space. You still need to learn from those techniques of exploit and vulnerability analysis, but you don't have the same number of points in your data set to make pass/no-pass decisions. You really need to change your way of thinking at the very beginning of the analysis process from the IDS-centric model of "suspicious or not suspicious" to "allowed or not allowed." That sounds easy on the surface, but not so much when you get hands-into exploit and vulnerability analysis. Then there's the argument (and current direction of the industry which Gartner/Richard has based their claims on) that takes the approach of basing IPS on existing IDSs. That is, taking an IDS, moving it to be in-band (versus out-of-band) and integrating firewall-like behavior into it. This is a perfectly acceptable solution for stopping some blatant types of attacks. Lot of the possible alerts and IDS can generate are definitely bad activities, but many more of them are more ambiguous - no matter what kind of detection methodologies you rely on. Sure you can stop those blatant ones, but what about all the rest? Don't kid yourself. This will not and cannot stop all attacks. Is it good enough though? Depends what kind of attacks you're most concerned about. These devices will do nothing for the advanced analysis required to find attacks against custom applications that application proxies have the potential to find. Why not get (or make) a box that does it all? Simple: computing resources. (ASIC, Network Processor, or otherwise!) If you could combine FULL IDS, FULLY stateful firewalling, FULL RFC protocol enforcement, FULL anomaly detection, FULL protocol decoding, FULL binary traffic analysis, etc. on one box... Well, it wouldn't be a security device, it'd be an end-station and you wouldn't need security devices anymore. To say IPS based on IDS -or- firewall -or- application proxy -or- etc. is a better technique without defining exactly what its better compared to, why, AND what it's WORSE at is irresponsible and ignorant. To say IPS based on ANYTHING will fully replace the auditing/forensic/policy monitoring/etc. capabilities allowed by IDS is even worse - no matter how you try to justify it. Made-up market demands or otherwise. Don't think those market demands are made up??? How do you explain: "Ranum): In private communications with Stiennon (the Gartner analyst), he offered the shocking fact that - for all that they are hyping IPS - the team at Gartner 'doesn't know anyone who is using an IPS in inline mode.' That runs utterly contrary to the perception they are trying to create that IPS is the 'wave of the future'" Anyways, the best solution for one environment is not going to be a market-wide best solution. I'm glad there are several other vendors who haven't completely succumbed to money-making hype and are taking a more responsible approach to researching these technologies. It's nice to see, and I applaud them all. Feeling like he's beating a horse that's already one step away from glue, -Gary [1]Forensic evidence from an IDS does not need to be used for prosecution to be useful. It's also good for general incident response and containment, policy enhancements, trending/tracking, admin/developer training, research, etc... ------------------------------------------------------------------------------- Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the world's premier technical IT security event! 10 tracks, 15 training sessions, 1,800 delegates from 30 nations including all of the top experts, from CSO's to "underground" security specialists. See for yourself what the buzz is about! Early-bird registration ends July 3. This event will sell out. www.blackhat.com -------------------------------------------------------------------------------
Current thread:
- Recent Gartner IDS/IPS report Gary Golomb (Jun 18)
- Re: Recent Gartner IDS/IPS report Stephen Samuel (Jun 18)
- Re: Recent Gartner IDS/IPS report Andreas Hess (Jun 22)
- Re: Recent Gartner IDS/IPS report Jeff Nathan (Jun 22)
- <Possible follow-ups>
- RE: Recent Gartner IDS/IPS report Carey, Steve T GARRISON (Jun 18)
- RE: Recent Gartner IDS/IPS report oherrera (Jun 19)
- RE: Recent Gartner IDS/IPS report Avi Chesla (Jun 19)
- RE: Recent Gartner IDS/IPS report Andre Yee (Jun 22)
- RE: Recent Gartner IDS/IPS report Golomb, Gary (Jun 22)
