Re: Generating Traffic to Stress Test IDS
From: Dragos Ruiu (dr@kyx.net)Date: 01/25/02
- Previous message: Jerry A. Shenk: "SHADOW - ssh autologon problem"
- In reply to: Ken Pohniman: "RE: Generating Traffic to Stress Test IDS"
- Next in thread: Greg Shipley: "Re: Generating Traffic to Stress Test IDS"
- Next in thread: Ken Pohniman: "RE: Generating Traffic to Stress Test IDS"
- Reply: Greg Shipley: "Re: Generating Traffic to Stress Test IDS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 25 Jan 2002 08:09:32 +0000 From: Dragos Ruiu <dr@kyx.net> To: <kenpohniman@yahoo.com>
This 40Mbps number is a potentially dangerous bit of misinformation most
nids vendors exceeded these drop thresholds a ways back.
The drop rate is dependent on a great many things, including the specific
ids software, the cpu speed, memory, nic type, bus type, os, capture
subsystem, rule loading and settings on the ids, etc...
I think you'll find IDSes esily today to go to 600Mbps+ speeds in some
typical scenarios.
Packet drop rate, at it's simplest is defined as the ratio of the number
of packets you should have seen/alerted/munged/whatever to the number
of packets you did get. Measuring this ratio under realistic conditions
is left as an excersize for the reader. (Hint: use a controllable,
accurate traffic source, and examine logs/statistics/whatever on the
receive side carefuly. Don't forget the background load. :-)
cheers,
--dr
-- Requisite Commercial Content and Disclaimers: http://cansecwest.com CanSecWest Network Security Training Conference - Vancouver B.C. - May 1-3 2002 OpenSnort IDS Sensors: http://www.sourcefire.comOn Fri, 25 Jan 2002 07:53:20 +0800 "Ken Pohniman" <kenpohniman@yahoo.com> wrote:
> From what I understand, a NIDS can typically handle up to 40Mbps of traffic > at any one time before starting to drop packets aggresively. An IDS > Balancer, like that from TopLayer Networks, will be required, especially if > you're talking about a GE network. > > Btw, regardless of what tool you use, does anyone knows how to check what is > the packet drop rate on the IDS? > > Thanks! > > -----Original Message----- > From: Chad Gough [mailto:chad131@yahoo.com] > Sent: Thursday, January 24, 2002 11:27 PM > To: focus-ids@lists.securityfocus.com > Subject: Generating Traffic to Stress Test IDS > > > Does anyone know of any good tools that can generate alot of network > traffic to see at what point an IDS starts dropping packets? > > Thanks, > Chad > > __________________________________________________ > Do You Yahoo!? > Great stuff seeking new owners in Yahoo! Auctions! > http://auctions.yahoo.com > > > _________________________________________________________ > Do You Yahoo!? > Get your free @yahoo.com address at http://mail.yahoo.com > >
- Previous message: Jerry A. Shenk: "SHADOW - ssh autologon problem"
- In reply to: Ken Pohniman: "RE: Generating Traffic to Stress Test IDS"
- Next in thread: Greg Shipley: "Re: Generating Traffic to Stress Test IDS"
- Next in thread: Ken Pohniman: "RE: Generating Traffic to Stress Test IDS"
- Reply: Greg Shipley: "Re: Generating Traffic to Stress Test IDS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|