RE: Newbie IDS questions

From: robert_david_graham (robert_david_graham@yahoo.com)
Date: 01/10/02


From: robert_david_graham <robert_david_graham@yahoo.com>
To: "'Mike Hrubes'" <MHrubes@wizmo.com>, FOCUS-IDS@SECURITYFOCUS.COM
Date: Wed, 9 Jan 2002 19:34:13 -0500 

BlackICE Guard does this.
Hogwash does it for Snort.

You have to consider the possibility of false-positives introducing problems
on the connection. The "Guard" product (from my company) contains a tuned
policy for this. There are tuned signatures sets by people who use Hogwash.

> -----Original Message-----
> From: Mike Hrubes [mailto:MHrubes@wizmo.com]
> Sent: Wednesday, January 09, 2002 12:30 PM
> To: FOCUS-IDS@SECURITYFOCUS.COM
> Subject: Newbie IDS questions
>
>
> Hi all,
>
> I'm new to the IDS world. I understand what an IDS does, and why you
> need it, but I have some questions on the technical aspect of IDS. We
> are planning on implementing an IDS in the near future. The idea that
> has been proposed is to put the IDS in the path between connections,
> rather than connected in promiscuous mode. The reason they want to do
> this is so they can also run a blocking software, like portsentry, to
> block unwanted scans, etc.
>
> Is this even possible to do? The idea is to use a linux
> server running
> snort. This box would have two interfaces to route the
> traffic through
> it, scanning the signatures at the same time.
>
> Possible/not possible? If possible, good idea/bad idea? Opinions in
> general?
>
> Thanks in advance,
>
> Mike Hrubes



Relevant Pages

  • Re: Newbie IDS questions
    ... Since I am one of the authors of Hogwash I feel qualified to respond to this. ... Hogwash works in bridging mode forwarding or dropping packets based on snort ... generate an alert and log the packet each time as well. ... I understand what an IDS does, ...
    (Focus-IDS)
  • RE: Newbie IDS questions
    ... I understand what an IDS does, ... Snort archives/web site for Hogwash. ... The skinny: If Hogwash receives a packet, ...
    (Focus-IDS)
  • Re: Value of "richer" signatures?
    ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
    (Focus-IDS)
  • User informix must be a Domain Member for ODBC Connection?
    ... My group is upgrading IDS from 9.40 to 11.50 on HPUX 11.23. ... Connection Failed: ... informix username in the original error output. ... "Domain Connections that Do Not Specify a Domain Name ...
    (comp.databases.informix)
  • Re: ids inquisition
    ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
    (Focus-IDS)