IDS mailing list archives
Re: Help in evaluating Inline IDS/IPS solution
From: "SecurityFocus" <securityfocus () mitchelhome com>
Date: Mon, 9 Jun 2003 09:06:24 -0500
One lab that has attempted to be a certification lab for IDS is a company out of chicago called Neohapsis. (www.neohapsis.com) They call it OSEC. The CEO/President of the company writes security articles for Network Computing Magazine. They are really well respected and they are working really hard to develop testing for Next Generation IDS/IPS as well. Thanks, SF. ----- Original Message ----- From: "Srinivasa Rao Addepalli" <srao () intotoinc com> To: "Ravi" <ravivsn () roc co in>; <focus-ids () securityfocus com> Sent: Friday, June 06, 2003 5:31 PM Subject: Re: Help in evaluating Inline IDS/IPS solution
Hi,Do IDS vendors really test the signature against the vulnerable applications, hardware platform of the application and version of application before releasing the signature? Do the IDS vendors claim this? If so, what is it I need to look for?SRINI> Yes. You need to look for this. Otherwise what is the value of signature? But, at the same time, all the signatures might not have been tested with real applications having the vulnerability. Think of number of protocols, applications, versions and hardware platforms they run. So, you need to first decide on what are the applications/platforms you need the security for. Then you find out from the IDS vendors on what applications/platforms they test with. Better the match and better the vendor for you. Though this differes from customer to customer, typical services in the enterprise market segement are HTTP, SMTP, POP3, IMAP, LDAP, RADIUS, SNMP, SSHv2/v3, Net8(SQLNET) etc.. Make sure that your IDS vendor tests with applications of above services before making signatures avaialble. For example, Apache and IIS are more popular webservers. Sendmail, qmail and Microsoft email exchange servers are popular email servers... Ask the vendor, how other signatures are tested? Typically vendors tend to test with available scripts, commerical/free vulnerablity
scanners.
Finally, I suggest you get the eval. copies and test the product
yourselves
with publicly available scripts, scanners to make a final judgement.From sensor technology perspective, I find that all the vendors seems to be having similar capabilities. But, I am trying to see the continued support on new attacks and vulnerabilities found. One vendor claims that they have 5 dedicated analysts looking at the vulnerabilities and updating signatures (if needed). Another vendors claims that they have more than 20 analysts doing this job. Can this be considered in my eval? Is it that other vendor exaggerating the number of resources they have for this
job.
SRINI> Yes. You can consider this in your eval. But make sure that the vendors are talking same language. It is possible that one vendor may be claiming all the human resources working on their product and other vendor may be indicating resources working on the vulnerability analysis and signature udpates.Performance: What is the best metric to look for? I feel HTTP1.0/1.1, SMTP, IMAP, NNTP, TELNET, POP3 connection rate and UDP throughput for different sizes is good metric. Is there anything should I look for?SRINI> More and more IDS are moving towards application intelligence. Due to this, the application connection rate needs to be considered as one of the performance measurements. But, just don't go by connection
rate.
You also need to look at the number of attacks they detect. Assuming the sensor technology is same, lesser the signature better the performance and poorer the attack detection rate. You need to judge the performance with number of attacks the sensor is able to detect and performance it gives.Are there any labs, which provide testing facilities for testing IDS/IPS with latest vulnerabilities and with real vulnerable applications? I am really looking for lab which provides facilities and allows us to test the IDS/IPS solution on regular basis.SRINI> I am not aware of any labs. But there are labs which certify the products. One thing which comes to my mind is 'icsalabs'.-- The views presented in this mail are completely mine. The company is not responsible for whatsoever. ------------------------------------------------------------------------ Ravi Kumar CH Rendezvous On Chip (i) Pvt Ltd Hyderabad, India Ph: +91-40-2335 1214 / 1175 / 1184 ROC home page <http://www.roc.co.in>--------------------------------------------------------------------------
-----
INTRUSION PREVENTION: READY FOR PRIME TIME? IntruShield now offers unprecedented Intrusion IntelligenceTM
capabilities
- including intrusion identification, relevancy, direction, impact and
analysis
- enabling a path to prevention. Download the latest white paper "Intrusion Prevention: Myths,
Challenges, and Requirements" at:
http://www.securityfocus.com/IntruVert-focus-ids2--------------------------------------------------------------------------
-----
--------------------------------------------------------------------------
-----
INTRUSION PREVENTION: READY FOR PRIME TIME? IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - including intrusion identification, relevancy, direction, impact and
analysis
- enabling a path to prevention. Download the latest white paper "Intrusion Prevention: Myths, Challenges,
and Requirements" at:
http://www.securityfocus.com/IntruVert-focus-ids2 --------------------------------------------------------------------------
-----
------------------------------------------------------------------------------- INTRUSION PREVENTION: READY FOR PRIME TIME? IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention. Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids2 -------------------------------------------------------------------------------
Current thread:
- Help in evaluating Inline IDS/IPS solution Ravi (Jun 04)
- Re: Help in evaluating Inline IDS/IPS solution Stephen Samuel (Jun 05)
- Re: Help in evaluating Inline IDS/IPS solution Lance Spitzner (Jun 05)
- RE: Help in evaluating Inline IDS/IPS solution Brian Laing (Jun 05)
- Re: Help in evaluating Inline IDS/IPS solution Srinivasa Rao Addepalli (Jun 06)
- Re: Help in evaluating Inline IDS/IPS solution SecurityFocus (Jun 09)
- <Possible follow-ups>
- RE: Help in evaluating Inline IDS/IPS solution Golomb, Gary (Jun 05)
