IDS mailing list archives
Re: signature based IDS/IPS effectiveness
From: "Jamie Riden" <jamie.riden () gmail com>
Date: Thu, 10 Jan 2008 10:20:13 +0000
On 10/01/2008, narccist tohell <mayur100 () gmail com> wrote:
Thanks Jamie and Stefano for noticing my issues, 90% of commercial database specific IDS/IPS systems do "signature matching" exploit detection. They are stateless and mostly based on snort. So does this mean that all they can do is stop public exploits. If someone modifies the exploit then the signatures will fail and by that means the appliances too ?
Hi there, The IDS is there to tell you you've been compromised and need to take action to sort it out. It doesn't in any way stop your database box being compromised. I used to look after a large-ish network of some 5K hosts and the thing that I noticed most often was outgoing portscans and IRC traffic from boxes which had been owned. If possible, I like to have the IDS run independently of the security arrangements for the actual hosts. I like to lock the network down so I'm pretty sure that the risk is low. Then I use IDS to make sure my confidence is not misplaced - as a sanity check if you like. Also, it is a great reassurance if other people are changing configs of your network. Metasploit v3 has pretty good IDS evasion code, especially for example to do with browser exploits embedded in HTTP. Doesn't matter too much, because most attackers, having owned a box will do very unstealthy things like scan a /8 looking for more boxes to compromise, or join an IRC channel. These secondary effects show up very well on snort with portscan logging. Your IDS has actually detected the intrusion, as it's meant to - although not as efficiently as it perhaps could have. As for securing a DB box, I'm not an expert and tend to use postgresql because I like it and it's free. I haven't played with IPS much either, so can't help there either. cheers, Jamie -- Jamie Riden / jamesr () europe com / jamie () honeynet org uk UK Honeynet Project: http://www.ukhoneynet.org/ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------
Current thread:
- Re: Preventing layer 3/4 evasions, (continued)
- Re: Preventing layer 3/4 evasions Jeremy Bennett (Jan 09)
- RE: Preventing layer 3/4 evasions Mike Barkett (Jan 07)
- signature based IDS/IPS effectiveness GMail (Jan 09)
- Re: signature based IDS/IPS effectiveness Stefano Zanero (Jan 09)
- Looking for feedback on anomaly-based IDS systems Libershal, David M. (Jan 09)
- Re: Looking for feedback on anomaly-based IDS systems p1g (Jan 10)
- Re: signature based IDS/IPS effectiveness Jamie Riden (Jan 10)
- Re: signature based IDS/IPS effectiveness GMail (Jan 10)
- RE: signature based IDS/IPS effectiveness Nelson Brito (Jan 10)
- Re: signature based IDS/IPS effectiveness Paul Schmehl (Jan 10)
- signature based IDS/IPS effectiveness GMail (Jan 09)
- Message not available
- Re: signature based IDS/IPS effectiveness Jamie Riden (Jan 10)
