|
|||||||||||
|
RE: [Snort-users] Re: [Snort-devel] IDS vs IPS
From: Gordon Cunningham <gacunningham(at)bellsouth.net>
Date: Wed Aug 27 2003 - 21:46:14 EDT
-----Original Message-----
Sent: Wednesday, August 27, 2003 8:34 PM To: Jason Cc: bwalder@spamcop.net; 'Mark Teicher'; 'Jeff Nathan'; Vkmobile@aol.com; snort-devel@lists.sourceforge.net; snort-users@lists.sourceforge.net Subject: Re: [Snort-users] Re: [Snort-devel] IDS vs IPS
<< File: signature.asc >> On Wed, 2003-08-27 at 18:36, Jason wrote:
Not quite. There are difference in the way firewalls and intrusion detection systems analyze data. For example, I have not seen a firewall that can identify a CodeRed attempt by name for example. Yeah, you can block HTTP methods and put limiters on URL's etc (you mentioned CP as an example which can do that with HTTP content stuff). But I have not come across a firewall with a 'signature set' like IDS' have them......yet. It is true that most firewalls are under-utilized. However, an IPS (being based on an IDS) has capabilities beyond a firewall. Policy violations (or network flow anomalies) can be detected by firewalls and cause some sort of reaction/enforcement (CP's SAM is one example). However, firewalls don't have statistical anomaly detection like some IDS' do. Let's draft a matrix of capabilities: Metric | Firewall | IDS | IPS
Signature | Limited packet | Extensive | See IDS
Analysis | inspection | signature sets |
| due to lack of | allow wide |
| rule set defin.| pattern match |
-----------------------------------------------------------
Protocol | Mostly present | Present | Present
validation | | |
-----------------------------------------------------------
Traffic flow| Present, that's| Present | Present
Anomaly Det.| what they do | | Present
-----------------------------------------------------------
Statisitcal | Absent | Present | Absent (???)
Anomaly Det.| | | (as of today)
-----------------------------------------------------------
Packet Log | Logging mostly | capable of | See IDS
| high level | logging content|
-----------------------------------------------------------
Protocol | Present | Absent | Present
normalizat | | |
ion | | |
===========================================================
Activity | Active | Mostly Passive | Active
If someone wants to take this further, feel free. But as you can see, IPS and firewalls are not quite alike (but neither are IPS and IDS! :)
Regards,
This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf Snort-devel mailing list Snort-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-devel Received on Thu Aug 28 10:24:42 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:09 EDT |
||||||||||
|
|||||||||||