|
|||||||||||
|
Re: IDS thoughts
From: Mike Frantzen <frantzen(at)nfr.net>
Date: Tue May 20 2003 - 14:25:23 EDT > You are joking, right ? There's a whole lot of research still open in the
> In the next few years, while established IDS products will strive to keep up
> When it comes to firewalling, we all agree: you just shut down everything
That naivety from the security device just doesn't cut it in the IDS space. Sit down and stare at several captures of HTTP transactions. Ones from IE, Netscape, Konq, Opera.... They all look different and this is where theory diverges from implementation. An anomaly in one is perfectly normal in the other. It gets worse, the transactions start looking differently depending on the server they talk to. Sure, so we can leave the client protocol models agnostic of the server type. But now you start to factor in that HTTP clients lie about what program they are. And certain venders are notorious for protocol variations between minor patch levels... Yes, pure anomaly detection is a very complex process and *VERY* difficult to create something that doesn't have a propensity towards false positives. Subtle changes in an environments usage patterns often occur suddenly and tend to come across as anomalies -- now the IDS/IPS admin gets inundated after acclimating to relatively few alerts. Thus you see many venders transitioning (have already done so) to doing anomaly detection where feasible, and "bad thing" detection when not. I'll make a standing offer, I will buy anyone a cookie that can describe their enterprise network usage adequately enough that would allow pure anomaly detction. Hint, you control all the clients versions and all their connections either terminate at your servers or your proxies.
.mike
INTRUSION PREVENTION: READY FOR PRIME TIME? IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention. Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids2 Received on Tue May 20 14:36:16 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:12 EDT |
||||||||||
|
|||||||||||