RE: GB IDS solutions

From: ARIAN EVANS (arian.evans@uscentral.org)
Date: 04/11/02


From: ARIAN EVANS <arian.evans@uscentral.org>
To: 'Stephane Auger' <stephane.auger@abovesecurity.com>
Date: Thu, 11 Apr 2002 15:10:01 -0500


> > Does anyone know of GB network IDS solutions other than ISS?

There's a number of vendors that claim GB; intrusion.com, etc.
IME Dragon, Cisco Netranger/SecureIDS, and Snort are faster than
ISS RS 5.0/5.5. Haven't tested RS 6.x for max throughput.

YMMV depending on underlying hardware and OS...

> Better yet has anyone implemented a non-ISS solution and how is it
> working?

We moved to Sourcefire's OpenSnort appliances (basically a 1U Intel
server chassis, bsd+snort and Sourcefire's management interface.)
http://www.sourcefire.com

I've replaced two higher-end Intel multi-proc servers, running RS
6.0 on Win2k w/one OpenSnort appliance. Due to the current performance
of that appliance, I am estimating I'll be able to replace about four
of our RS 6.0/Intel/2k sensors, at least, but I don't have hard metrics
yet, and we've done very little sensor tuning so far, so we might
do better yet...

> What type of
> > hardware are you using? What were your costs approx. per sensor?

Contact Sourcefire on pricing...Prepackaged *appliances* seem to
all run about the same on cost, ISS, Symantec, Intrusion.com,
Dragon, Cisco SecureIDS, etc, for equal underlying hardware.

> > I will be needing GB capable sensors but believe there must
> be another way to go besides ISS (to much $$$). Has anyone used Snort with

> GB Ethernet cards?

Talk to the guys at Sourcefire about this; I talked w/Marty at length
about this last year, and decided that was not the route I wanted to
go since above the NIDS layer (on our 2k stuff) w/GigE or not, 300mbs
seems about the max that can be processed. Unless something has changed
recently in the GigE/NDIS/NIDS world, or I'm way off on my testing, you
might look at a different approach:

Have you thought about creating a farm of sensors with a central database
and using either VTP in conjunction w/specific span ports for monitoring
specific VLANs (sensor1--VLAN 101, sensor2--VLAN 202, etc.; all sensor
data sent to the same DB)? If you are grabbing this all from the same
broadcast domain, how about using a device that can do traffic mirroring,
or network taps into a concentrator, and break up the traffic by IP range
across a sensor farm?

There's several ways to do this, and without knowing if this is all one
broadcast domain, or if you have a perimeter you are monitoring from
(and thus can use inline devices...), or whether network taps on internal
switches is the better way to go in your scenario, it's hard to say.

You'd spend some money up front for hardware to aggregate/distribute
traffic, but could build your own sensors *nix+snort+intel cheaply
and keep your NIDS centralized.

Arian J. Evans
Senior Information Systems Security Engineer
U.S. Central Credit Union



Relevant Pages

  • Re: How to choose an IDS/FW MSS provider
    ... Yes, I realized, after I sent my email, that ISS also had a problem... ... customer to do OS policy enforcement on their internal network. ... >> hackers to read the source code and look for ways to compromise it. ... > machines on the Internet, even in niches without a software monopoly. ...
    (Focus-IDS)
  • Re: IDS deployment outside FW?
    ... your IDS sensors should never be active on the ... network that they are monitoring (unless you're doing some sort of ... able to craft the monitoring rules to focus on those devices. ...
    (Focus-IDS)
  • Re: IDS on a load balanced BGP network
    ... try to take out all nodes on the network. ... >In this scenario, I would recommend deploying 2 sensors, ... Traffic from multiple SPAN ports of multiple switches ... >deployment modes for both 10/100 Ethernet links as well ...
    (Focus-IDS)
  • RE: Best IPS system?
    ... ::: network of my business. ... : My two cents: ISS is atrocious. ... TippingPoint and Sourcefire have the best IPSs with the smartest team ... just not a great marketing team with glossy brochures. ...
    (Focus-IDS)
  • Re: Cisco CTR
    ... > passive sensors deployed anywhere near the entire environment. ... > everywhere some idiot has access to a network jack. ... It depends on the level of visibility you need into your network ... Sourcefire Inc. - 290-1616 Sourcefire: ...
    (Focus-IDS)

Loading