IDS mailing list archives

Re: Help in evaluating Inline IDS/IPS solution


From: "Srinivasa Rao Addepalli" <srao () intotoinc com>
Date: Fri, 6 Jun 2003 15:31:31 -0700

Hi,
  


      Do IDS vendors really test the signature against the vulnerable 
applications, hardware
      platform of the application and version of application before 
releasing the
      signature? Do the IDS vendors claim this?  If so, what is it I 
need to look for?

SRINI> Yes. You need to look for this. Otherwise what is the
value of signature? But, at the same time, all the signatures might
not have been tested with real applications having the vulnerability.
Think of number of protocols, applications, versions and hardware
platforms they run. So, you need to first decide on what are
the applications/platforms you need the security for. Then you find
out from the IDS vendors on what applications/platforms they test 
with. Better the match and better the vendor for you. Though this
differes from customer to customer, typical services in the
enterprise market segement are HTTP, SMTP, POP3, IMAP,
LDAP, RADIUS, SNMP, SSHv2/v3, Net8(SQLNET) etc..
Make sure that your IDS vendor tests with applications of above
services before making signatures avaialble. For example, Apache
and IIS are more popular webservers. Sendmail, qmail and Microsoft
email exchange servers are popular email servers...

Ask the vendor, how other signatures are tested? Typically vendors
tend to test with available scripts, commerical/free vulnerablity scanners.

Finally, I suggest you get the eval. copies and test the product yourselves
with publicly available scripts, scanners to make a final judgement.


      From sensor technology perspective, I find that all the vendors 
seems to be having
      similar capabilities. But, I am trying to see the continued 
support on new attacks
      and vulnerabilities found.
      One vendor claims that they have 5 dedicated analysts looking at 
the vulnerabilities
      and updating signatures (if needed). Another vendors claims that 
they have more
      than 20 analysts doing this job. Can this be considered in my 
eval? Is it that other
      vendor exaggerating the number of resources they have for this job.

SRINI> Yes. You can consider this in your eval. But make sure that
the vendors are talking same language. It is possible that one vendor
may be claiming all the human resources working on their product and
other vendor may be indicating resources working on the vulnerability
analysis and signature udpates. 

      Performance:
      What is the best metric to look for? I feel HTTP1.0/1.1, SMTP, 
IMAP, NNTP,
      TELNET, POP3 connection rate and UDP throughput for different 
sizes is good
       metric. Is there anything should I look for?

SRINI> More and more IDS are moving towards application intelligence.
Due to this, the application connection rate needs to be considered as
one of the performance measurements. But, just don't go by connection rate.
You also need to look at the number of attacks they detect. Assuming the
sensor technology is same, lesser the signature better the performance and
poorer the attack detection rate. You need to judge the performance with
number of attacks the sensor is able to detect and performance it gives.

      Are there any labs, which provide testing facilities for testing 
IDS/IPS with latest
      vulnerabilities and with real vulnerable applications? I am really 
looking for lab
      which provides facilities and allows us to test the IDS/IPS 
solution on regular basis.


SRINI> I am not aware of any labs. But there are labs which certify the
products.  One thing which comes to my mind is 'icsalabs'.




-- 


The views presented in this mail are completely mine. The company is not
responsible for whatsoever.
------------------------------------------------------------------------
Ravi Kumar CH
Rendezvous On Chip (i) Pvt Ltd
Hyderabad, India
Ph: +91-40-2335 1214 / 1175 / 1184

ROC home page <http://www.roc.co.in>




-------------------------------------------------------------------------------
INTRUSION PREVENTION: READY FOR PRIME TIME?

IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities 
- including intrusion identification, relevancy, direction, impact and analysis 
- enabling a path to prevention.

Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: 
http://www.securityfocus.com/IntruVert-focus-ids2
-------------------------------------------------------------------------------

-------------------------------------------------------------------------------
INTRUSION PREVENTION: READY FOR PRIME TIME?

IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities 
- including intrusion identification, relevancy, direction, impact and analysis 
- enabling a path to prevention.

Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: 
http://www.securityfocus.com/IntruVert-focus-ids2
-------------------------------------------------------------------------------


Current thread: