
IDS mailing list archives
Re: Hi, I want to study IPS
From: Greg Martin <greg () ddos com>
Date: 14 May 2004 18:13:02 -0000
In-Reply-To: <000101c438ab$3fda2300$9b97a8c0@cleoa>
IDS and IPS are using the same tools and same abilities. They are actually the same. IPS came out as a "catch phrase" as a "different" solution than IDS. Please refer to the recent posting from "Frank Knobbe" and "Jason" as a reference. Don't get fooled in terminology and remember there is no "one" solution. Many of us use 4 or 5 types of systems to pull everything together into an IDS solution. Best of luck with your task. HAGO. Wil Veno wjveno () shaw ca shawn () whitehats ca
Wil, you are right that some IPS products use similar techniques as IDS (inline packet filtering with patterns) but not all of them use that technique. Some vendors use a baseline of the network and take action if the baseline changes drasticly. Some use a 'negative space' technique which allows only valid traffic and considers all other traffic as a dos and drops it completely. The main diference is that IPS takes action as proactively as possible were an IDS is designed to monitor and alert. You can modify some IDS systems to have IPS features with varying results but if we don't have them catagorized with different names it would be rather confusing. You should never try to have one machine do everything, that not only limits your functionality but creates a single point of failure. Where a IDS can have sensors all over the network and external links, you generally only want an IPS protecting your border. Greg --------------------------------------------------------------------------- ---------------------------------------------------------------------------
Current thread:
- FW: Hi, I want to study IPS Tarek Amr Abdullah (May 12)
- <Possible follow-ups>
- RE: Hi, I want to study IPS Arun Vishwanathan (May 12)
- RE: Hi, I want to study IPS Arun Vishwanathan (May 12)
- RE: Hi, I want to study IPS Josh Mills (May 12)
- RE: Hi, I want to study IPS (infor) urko zurutuza (May 13)
- RE: Hi, I want to study IPS Velasquez Venegas Jaime Omar (May 13)
- Re: Hi, I want to study IPS Greg Martin (May 14)
- RE: Hi, I want to study IPS Omar Herrera (May 16)
- Re: Hi, I want to study IPS Raistlin (May 22)
- Re: Hi, I want to study IPS Greg Martin (May 25)
- Re: Hi, I want to study IPS Stefano Zanero (May 25)
- RE: Hi, I want to study IPS Ingevaldson, Dan (ISS Atlanta) (May 14)
- RE: Hi, I want to study IPS Runion Mark A FGA DOIM WEBMASTER(ctr) (May 25)
- Re: Hi, I want to study IPS Ali Rajput (May 26)
- Testing IDS/IPS Signatures Securecatalyst (May 28)
- Re: Testing IDS/IPS Signatures Andrea Barisani (May 28)
- Re: Testing IDS/IPS Signatures Ron Gula (May 28)
- Re: Hi, I want to study IPS Ali Rajput (May 26)