Re: Evaluation for IDS

From: Kurt Seifried (bugtraq@seifried.org)
Date: 09/28/01


Message-ID: <003701c14812$6eba5140$6400030a@seifried.org>
From: "Kurt Seifried" <bugtraq@seifried.org>
To: "hu jinhua" <hujh@neusoft.com>, <focus-ids@securityfocus.com>
Subject: Re: Evaluation for IDS
Date: Fri, 28 Sep 2001 05:40:53 -0600

One simple way would be to shove a lot of traffic through and then launch
attacks (get code from packetstorm or similar). You know what you are
sending, and by checking the reports can easily figure out what % of attacks
are detected, also how good the info is (i.e.: attack foo detected" verses
"attack foo detected, go find all your win2k servers and make sure patch
#xxx is applied"). Plus there are things like Dug Song's frag router and
other tools you can use to make the IDS's life more realistic (you better
believe attackers use this stuff).

Kurt Seifried, kurt@seifried.org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://www.seifried.org/security/

----- Original Message -----
From: "hu jinhua" <hujh@neusoft.com>
To: <focus-ids@securityfocus.com>
Sent: Friday, September 28, 2001 12:00 AM
Subject: Evaluation for IDS

> I need help about testing methodology for IDS, or
> criteria about evaluating IDS. who can tell me about
> this.
> Someone who have knowledge about this please
> mail me. My E-mail address is hujh@neusoft.com.
> Thanks very much!
>



Relevant Pages

  • RE: Intrusion Prevention
    ... Coverage what can it detect; this covers basic attacks, ... IDS purchase. ... While doing these implementations and while working in an IDS vendor I ... sometimes we're told that we cannot see the testing methodology upfront. ...
    (Focus-IDS)
  • RE: Changes in IDS Companies?
    ... This means you need a standard IDS sitting behind it/next to it watching the ... Things like port scans and DoS attacks ... >>> If people are running insecure web servers, ... > Pretty sad state of affairs, when people don't update their patches at ...
    (Focus-IDS)
  • RE: Best Method(s) for signature verification.
    ... on this list - and other IDS lists - for the means to test their IDS ... When I say we use IDS Informer for our signature recognition testing, ... should point out that we do NOT use all the default attacks! ... (IIS attacks run against Apache web servers on Unix - "real ...
    (Focus-IDS)
  • Re: How to choose an IDS/FW MSS provider
    ... First, "recording everything" is not what IDS's were EVER meant for, ... others can create "audit" trails of every web request, every mail, every ... >detect attacks by inspecting layer 3 headers for prohibited IP ... >facility with an IDS or IPS deployed. ...
    (Focus-IDS)
  • Re: Alarming (was protocol analysis)
    ... Obviously, there are different ways to "detect" attacks, but John uses the ... no one should ever "rely" on any IDS for our ... As for Johns Metaphor of the motion sensor vs the pressure sensor, ... toward Intrusion Prevention as opposed to just Intrusion Detection. ...
    (Focus-IDS)