RE: Generating Traffic to Stress Test IDS

From: Simon Edwards (SEdwards@toplayer.com)
Date: 01/25/02


From: Simon Edwards <SEdwards@toplayer.com>
To: 'Greg Shipley' <gshipley@neohapsis.com>, focus-ids@lists.securityfocus.com
Date: Fri, 25 Jan 2002 13:13:00 -0500

Yes we handle fragmentation, and in most cases we will re-fragment before
passing to the IDS - another note we are also looking to put VLAN tag
removal into the next release, which will be out c end of Q1

Simon

________________________________________________
Simon Edwards
Technical Evangelist
Top Layer Networks
US Office : 508 870 1300 x230
UK Office : +(44) 1252 748509
UK Mobile: +(44) 7971 959170
www: www.TopLayer.com <http://www.TopLayer.com>
email: sedwards@toplayer.com <mailto:sedwards@toplayer.com>
 
"Perfecting the Art of Network Security"
----------------------------------------------------------------------------
--------

-----Original Message-----
From: Greg Shipley [mailto:gshipley@neohapsis.com]
Sent: 25 January 2002 17:32
To: focus-ids@lists.securityfocus.com
Cc: kenpohniman@yahoo.com; chad131@yahoo.com; Dragos Ruiu
Subject: Re: Generating Traffic to Stress Test IDS

On Fri, 25 Jan 2002, Dragos Ruiu wrote:

> This 40Mbps number is a potentially dangerous bit of misinformation most
> nids vendors exceeded these drop thresholds a ways back.
*snip*
> Packet drop rate, at it's simplest is defined as the ratio of the number
> of packets you should have seen/alerted/munged/whatever to the number
> of packets you did get. Measuring this ratio under realistic conditions
> is left as an excersize for the reader. (Hint: use a controllable,
> accurate traffic source, and examine logs/statistics/whatever on the
> receive side carefuly. Don't forget the background load. :-)

Just to add to what Dragos has stated, saying that NIDS drops at xMbps is
like saying cars can go as fast as 90 mph.

Obviously it depends on the car.

Side note: does anyone know how TopLayer handles fragmentation?

-Greg



Relevant Pages

  • Firewall Tester 0.7
    ... I've just released version 0.7 of my Firewall Tester, ... * fragmentation option for injected packets for both firewall and IDS testing modes ...
    (Pen-Test)
  • Firewall Tester 0.7
    ... I've just released version 0.7 of my Firewall Tester, ... * fragmentation option for injected packets for both firewall and IDS testing modes ...
    (Focus-IDS)
  • Re: non-random IP IDs
    ... >>> unique over a short period of time so fragmentation can work properly. ... > ids seems too great to justify for each packet sent. ... to frag a packet and stick whatever data you want into it; ...
    (FreeBSD-Security)
  • Re: Howto embed select statements into other select statements
    ... (select table1.co/table2.co ratio ... but the problem is that the query: ... I still get a ratio=null for those ids that do ... Would that work when I am already counting on table2? ...
    (comp.databases)