RE: On IDS Evasion, Vulnerabilities, and Vendor Hype

From: McCammon, Keith (Keith.McCammon@eadvancemed.com)
Date: 10/04/01


Message-ID: <BB7FD4FF9E440648A731452E5D341FB0654660@hitsexchange01.advance-med.com>
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: 'Eric Hacker' <hacker@vudu.net>, IDS Focus <FOCUS-IDS@SECURITYFOCUS.COM>, IDS List <ids@uow.edu.au>, bugtraq@securityfocus.com
Subject: RE: On IDS Evasion, Vulnerabilities, and Vendor Hype
Date: Thu, 4 Oct 2001 09:25:27 -0400 


>Recently a disturbing event played out in the IDS world. A security
>company released an advisory regarding the ability to bypass IDS
>signatures. This is disturbing because it conveys the impression that
>otherwise, it was not possible to bypass IDS systems. This is not
>true. IDS, especially Network IDS, is not mathematics. It is more
>like psychology; it is far from perfect.

To my knowledge, this was never implied in any of the advisories, nor was it
the intended message. The advisories were pretty clear regarding the fact
that *this* method could be used to evade an IDS (or several, for that
matter).

>signatures that are supposed to detect those attacks. To release all
>such methodologies as advisories at this stage of maturity in the
>technology is pointless, unless one is seeking publicity.

You are wrong. You are dead wrong. This follows the logic that OS vendors
and the folks at eEye, SF, etc. shouldn't release exploits until *all*
exploits for a given system are known. Full disclosure forces us to look at
things in a different light, and follow one vulnerability to yet another.
And so we patch the new one as well.

>Eeye cast the first stone with their advisory %u encoding IDS bypass
>vulnerability (http://www.securityfocus.com/advisories/3552).
>Certainly the issue that Eeye discovered is an important one and
>needed to be made public. The practice of marketing an organization's
>name through advisories is what is not necessary.

eEye, like just about any other security firm, announced the vulnerability
under their name. This isn't marketing, this gives the report credibility.
This also gives credit where credit is due.

If the release under their name brings in some business, so be it. They do
good work, and they uncovered one of the worst IIS holes to date. I'd hire
'em in a second.

>Customers who fall prey to vendor hype and believe that they have
>bought security.

Not the vendor's fault. Any semi-competent security (or even networking)
professional, knows that security is an on-going process that cannot be
bought.

>The system of trust that vendors release advisories to promote
>full disclosure and not to further their own interests.

How is that a vulnerability? You're not making sense.

>Eric Hacker, CISSP, GCIA, MCSE, CCSE

Nice collection.

Keith



Relevant Pages

  • RE: IDS and Spywares
    ... > a network based security control has better visibility than a host based ... Just as we do in IDS and network traffic analysis. ... > made spyware, or trojan, or any other kind of malware where you can install ...
    (Focus-IDS)
  • RE: Recommending an IDS system
    ... Not trying to make this a Cisco commercial, but I too am very satisfied with Cisco. ... We implemented an IDSM2, sensor device, and Cisco Security Agent for Host Intrusion Prevention. ... Subject: Recommending an IDS system ...
    (Security-Basics)
  • Re: Is IDS/IPS worthless?
    ... >>firewall instead of in front of it should BOTH ... >>fill in the gap left by the false sense of security firewalls give (a ... >IDS technology and I certainly believe in the usefullness of IDS. ... that is confusing IDS and NIDS together. ...
    (Focus-IDS)
  • RE: Firewalls (was Re: IDS evaluations procedures)
    ... but having setup security systems ... And of course many of the early IDS problems burned a lot of people (too ... Struggling / What's after firewalls? ... expertise to this approach, be it for one set of tools or everything. ...
    (Focus-IDS)
  • Re: Is IDS/IPS worthless?
    ... > This shut him up, for a while, but it highlighted a growing trend I am ... > bought and IDS and it just sat in a rack and did nothing" a lot ... a definite plus in security. ... But we may learn something from watching PKI in the last ...
    (Focus-IDS)

Quantcast