Snort mailing list archives
Re: flow_depth and WMF exploit
From: Frank Knobbe <frank () knobbe us>
Date: Thu, 05 Jan 2006 10:52:35 -0600
On Thu, 2006-01-05 at 11:33 -0500, Matthew Watchinski wrote:
3. Http_inspect was designed on purpose to ignore most if not all server response traffic. If you set flow_depth to 0 and stream4_reassemble to both all, you will take a 80% to 90% performance hit. This is probably ok if you have sub 10 meg links. If you don't this is not ok, especially if you are in an inline configuration.
Right. It has to be a balance between performance and inspection-ability. Either you look at a lot of packets, but not very closely, or you analyze deeper, but not as many. Unfortunately that means that when networks get faster and faster, IDSes are analyzing less and less data. I don't want to bring up the whole IDS-is-dead threat again, but it seems that the days IDSes are less capable inspecting traffic every year. Seems to me that they are moving from a packet analysis tool to a flow analysis tool, usable for profiling (behavioral, RNA, and stuff like that). -Frank -- It is said that the Internet is a public utility. As such, it is best compared to a sewer. A big, fat pipe with a bunch of crap sloshing against your ports.
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- flow_depth and WMF exploit Jason Haar (Jan 03)
- Re: flow_depth and WMF exploit Frank Knobbe (Jan 04)
- Re: flow_depth and WMF exploit purplebag (Jan 04)
- Re: flow_depth and WMF exploit Jason Haar (Jan 04)
- Re: flow_depth and WMF exploit Matthew Watchinski (Jan 05)
- Re: flow_depth and WMF exploit Frank Knobbe (Jan 05)
- Re: flow_depth and WMF exploit Jason (Jan 05)
- Re: flow_depth and WMF exploit Frank Knobbe (Jan 05)
- Re: flow_depth and WMF exploit Jason (Jan 05)
- Re: flow_depth and WMF exploit Frank Knobbe (Jan 05)
- Re: flow_depth and WMF exploit Jason (Jan 05)
- Re: flow_depth and WMF exploit Jason Haar (Jan 05)
- Re: flow_depth and WMF exploit purplebag (Jan 04)
- Re: flow_depth and WMF exploit Frank Knobbe (Jan 04)
- <Possible follow-ups>
- RE: flow_depth and WMF exploit Ron Jenkins (Jan 03)
- Re: flow_depth and WMF exploit Jason Haar (Jan 03)
- Re: flow_depth and WMF exploit Brian Caswell (Jan 04)
- Re: flow_depth and WMF exploit Tom Le (Jan 03)
- Re: flow_depth and WMF exploit Jason Haar (Jan 03)
