Generating Traffic to Stress Test IDS

From: Francisco Saa Munoz (fsaa@cibersecurity.com)
Date: 01/24/02


From: Francisco Saa Munoz <fsaa@cibersecurity.com>
To: <focus-ids@lists.securityfocus.com>
Date: Thu, 24 Jan 2002 19:08:29 +0100

Chad Gough wrote:

> Does anyone know of any good tools that can generate alot of network
> traffic to see at what point an IDS starts dropping packets?

Normally I use a 'megamix' of tools like tcpblast to probing network
and estimating its throughoutput.
Also a set of scanners (nessus, vetescan, etc) and DoS (bubonic, land...)
probes at the same time, to calculate the ability of IDS to block all
kind of packets, normally the packets are coming from a random IP (spoofed
o.c.)to probe he speed.

Use this bestial probe under 1 minute, mixing the tools, with
the power of bash script ;)

Ah, and of course is a GNU/GPL set of tools _ALWAYS_, I spend 3 weeks to set
the test ready for all environments. So I think all people can do it in
less
time than me.

This is the way to exceed the limit.

--
Francisco Saa Munoz
Security Consultant
--
Linux User #119288
Proud mame.dk user #115087
--
"My english is poor, I know it"



Relevant Pages

  • Re: Recent anti-NIDS Gartner article
    ... packets and throughput of traffic is not suffered by IDS. ... Some reasons why I feel Inline IDSes don't require expensive ... if the packets come out of order (people ... then tap IDS does not even know and packets ...
    (Focus-IDS)
  • Re: Test scripts for NIDS
    ... If you're using tcpreplay for performance testing, ... >> packets and they are being dropped? ... > the IDS catches everything. ... > increasing speeds until the IDS output changes (usually by failing to detect ...
    (Pen-Test)
  • RE: session logging IDS
    ... you to go back up to the beginning of the buffer to get some previous history. ... Subject: session logging IDS ... saying you can go back and review packets previous from when the sniffer was ...
    (Focus-IDS)
  • Re: Signature and Traffic generation
    ... Make sure that you're not only generating "signatures" but that they are ... Many of the low-end packet grepping IDS fall prey to this ... They're doing real sessions ... You may want to just capture packets from a live network under varying ...
    (Focus-IDS)
  • RE: GB IDS solutions
    ... Just a comment on "Gigabit" IDS... ... whether the packets are part of valid TCP/IP/UDP transactions ... This test is the equivalent of a car-maker saying their car goes ...
    (Focus-IDS)