Re: ncircle's IP360

From: Bennett Todd (bet@rahul.net)
Date: 10/10/01


Date: Wed, 10 Oct 2001 09:42:25 -0400
From: Bennett Todd <bet@rahul.net>
To: Konrad Pociask <kpociask@hotmail.com>
Subject: Re: ncircle's IP360
Message-ID: <20011010094225.A13760@rahul.net>


2001-10-09-23:25:54 Konrad Pociask:
> Has anyone tried ncircle's IP360?

I haven't, yet. I've spoken with people who have, and have talked
with folks from nCircle (nee Hiverworld).

> I've heard some positive news about the product's performance
> running on a Gigabit network.

That's the claim, and I find it believable.

> Supposedly running at full wire-speed, does anyone know how this
> IDS differentiates itself from other products allowing it to run
> so fast.

The main way is they couple a vulnerability scanner to the IDS. The
vuln scanner periodically probes the net that the IDS is sniffing,
examining all machines on the net, classifying 'em by OS, and
locating services that might have known holes [i.e. for which there
are known signatures].

The list of candidate vulnerabilities is then used to tune the
sniffer; it only _looks_ for patterns for which the actual install
systems might be vulnerable. Fix all your potential holes and it
isn't looking for anything. Leave no more than a handful and it's
got a very short sig list.

The heart of this gizmo is the vuln scanner and its integration with
the IDS.

-Bennett






Relevant Pages

  • RE: Scanners and unpublished vulnerabilities - Full Disclosure
    ... The VNA seems like a fair solution. ... I would also like to further emphasize the point of proprietary IDS ... >> vulnerability and searches for more information on that vulnerability ... Many companies treat security breaches in a reactive ...
    (Pen-Test)
  • Re: IDS is dead, etc
    ... I think we are on the same page as to the utility of IDS systems. ... I really like your description of NIDS as AV scanners for the network. ... **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo ...
    (Focus-IDS)
  • Re: On IDS Evasion, Vulnerabilities, and Vendor Hype
    ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... encoding, unlike %u encoding." ... How long was it before some vendors ... > vulnerability. ...
    (Focus-IDS)
  • RE: "false positive" inanity
    ... What if you have a REALLY large network? ... > What Im trying to get across here is a revision to the IDS ... > configuration blinding or post-event vulnerability analysis. ... > Whereas some IDS vendors actually brag about how many signatures their ...
    (Focus-IDS)
  • On IDS Evasion, Vulnerabilities, and Vendor Hype
    ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... IDS vendors sometimes must completely rewrite parts of their engines ... Eeye cast the first stone with their advisory %u encoding IDS bypass ... vulnerability. ...
    (Focus-IDS)