[fw-wiz] Corporate H/N IPS

From: Talisker (talisker@networkintrusion.co.uk)
Date: 12/13/02


From: "Talisker" <talisker@networkintrusion.co.uk>
To: <firewall-wizards@honor.icsalabs.com>
Date: Fri Dec 13 08:04:02 2002

Hi
It's that time when I need to seriously look at updating the site.
http://www.networkintrusion.co.uk
Two new categories will be Host and Network Intrusion Prevention Systems, or
to be more precise Corporate IPS.

Firstly the definitions; by Corporate I mean that they can be managed
remotely and they will report into a central console ie not just the local
host.

Intrusion Prevention System (IPS). More proactive than the traditional
IDS, they actively block traffic deemed as malicious, almost like a firewall
but using IDS techniques to block an attack.

Host IPS. A HIPS will block an attack aimed at the Host upon which it is
situated, previous names for a HIPS have included Network Node IDS (NNIDS)
or personal firewall. To quote nss
"It binds closely with the operating system kernel and services, monitoring
and intercepting system calls to the kernel or APIs in order to prevent
attacks".
A HIPS should not to be confused with a HIDS which looks at the host Event
or Sys logs, though many HIPS incorporate HIDS and File Integrity Checking.
examples of HIPS are: Entercept and Intrusion's SHS (Stormwatch)

Network IPS. What used to be called an inline IDS, it's an IDS with 2
interfaces, it will block those packets that trigger the criteria laid down
by the IDS. examples TippingPoint UnityOne and RealSecure Guard

I'm hoping to get the pages up with a general overhaul over Christmas, my
real job is keeping me too busy these days, so many incidents, so little
time!

I'm looking for a good starting place and therefore looking for lists
containing HIPS and NIPS to start me off on the research, in return I will
collate all the information and feed a summary back into the list.

Bibliography: NSS http://www.nss.co.uk who have just published a review on
gigabit IDS

Taliskers Network Security Tools
http://www.networkintrusion.co.uk



Relevant Pages

  • Re: IDS is dead, etc
    ... > wouldn't call 'em an IDS, I think they're something different, much ... the host. ... Ensure Reliable Performance of Mission Critical Applications ... Precisely Define and Implement Network Security and Performance Policies ...
    (Focus-IDS)
  • RE: IDS
    ... Intrusion Detection System ... It is used to monitor traffic or activity on a network or host for signs ... Network based tools used for IDS: ...
    (Security-Basics)
  • Re: how to find hidden host within LAN
    ... I would also recommend placing an IDS (intrusion detection ... in a manner where they are "hidden" on the network by not using an IP ... In the last week i notice in the iptables logs that a host within ... my lan is doing a lot of traffic. ...
    (RedHat)
  • RE: Host Based IDS Recommendations?
    ... Subject: Host Based IDS Recommendations? ... Precisely Define and Implement Network Security & Performance ...
    (Focus-IDS)
  • Re: 2 pc network - cant see host files from pc 2 on pc 1
    ... If the second card is lost on HOST PC then DSL Internet does not connect. ... Ditch the second network card in the one ...
    (microsoft.public.windowsxp.security_admin)