Re: [fw-wiz] How should an Internet connection/firewall be designed?
- From: Dave Piscitello <dave@xxxxxxxxxxx>
- Date: Mon, 22 Jan 2007 09:42:42 -0500
This would be a legitimate and perhaps interesting application of an external IDS, but automated correlation is still relatively unexplored territory. I suspect that few organizations that actually do a CBA conclude this is a priority allocation of time, talent and technology.
To your observation about "seeking professional help": I imagine that any organization that would insist on such alarms *and* insist that IT staff actually investigate/attend would experience sufficiently high staff attrition rates to cause them to reconsider.
Carson Gaspar wrote:
Dave Piscitello wrote:begin:vcardKaas, David D wrote:How many companies have an IPS/deep-packet-inspection device between theI honestly don't see a lot of this and unless there's a specific DOS prevention issue, I don't see a lot of point in policing traffic that I expect my firewall to block.
firewall and the border router?
Back when I still did security for a living, I was a supporter of having an IDS device between your border router and your external firewall. However it was not for the reasons most folks might think. I wanted the external IDS in logging-only (no alarms) mode, purely for forensic and legal purposes. When we saw something funky on our internal/DMZ nets, we could look at the external logs to see if it was part of an attack pattern.
Of course there is a cost/benefit analysis that has to be done to determine if the data mining is worth the cost of the device.
I agree that anyone who has alarms enabled from an outside-the-firewall IDS probably ought to go see a professional about their paranoia issues...
fn:David Piscitello
n:Piscitello;David
adr;dom:;;3 Myrtle Bank Lane;Hilton Head;SC;29926
email;internet:dave@xxxxxxxxxxx
x-mozilla-html:FALSE
url:http://hhi.corecom.com/weblogindex.htm
version:2.1
end:vcard
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- References:
- [fw-wiz] How should an Internet connection/firewall be designed?
- From: Kaas, David D
- Re: [fw-wiz] How should an Internet connection/firewall be designed?
- From: Dave Piscitello
- Re: [fw-wiz] How should an Internet connection/firewall be designed?
- From: Carson Gaspar
- [fw-wiz] How should an Internet connection/firewall be designed?
- Prev by Date: Re: [fw-wiz] Benefits of Network Extention Mode vs IPsec
- Next by Date: Re: [fw-wiz] fwtk users?
- Previous by thread: Re: [fw-wiz] How should an Internet connection/firewall be designed?
- Next by thread: Re: [fw-wiz] How should an Internet connection/firewall be designed?
- Index(es):