Symantec Gateway Security

From: Dante Mercurio (dmercurio@ccgsecurity.com)
Date: 06/19/02


Date: Wed, 19 Jun 2002 12:02:42 -0400
From: "Dante Mercurio" <dmercurio@ccgsecurity.com>
To: <focus-ids@securityfocus.com>

I have a customer interested in this device because of it's all
encompassing border security features, including IDS. I have never
installed one of these so this information is here-say from a symantec
engineer. According to him, the IDS on this device has about 80
signatures, and they can directly change security policy by adding
blocked IP's to the device. Either the rules are on, or off. In
addition, there is no way to add exceptions to this (like root DNS), and
no way to edit the block time. It would appear that a DOS on this system
would be very easy with forged packets once you know what signatures
it's using. In addition, the signatures are updated with their Live
Update subscription. Anyone know if this means the signatures pushed
down are automatically enabled?

Anyone have any further info on this device? Should I steer my customer
away from it?

M. Dante Mercurio, CCNA, MCSE+I, CCSA
dmercurio@ccgsecurity.com
Consulting Group Manager
Continental Consulting Group, LLC
www.ccgsecurity.com



Relevant Pages

  • Re: Value of "richer" signatures?
    ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
    (Focus-IDS)
  • RE: Value of "richer" signatures?
    ... Is it that much faster to do "protocol parsing" than ... > Here's an example of how the newer IDS signatures help ... > Let's say you are using a simple packet grepping IDS ...
    (Focus-IDS)
  • RE: Testing IDS/IPS Signatures
    ... can a scanner be used to validate the IDS ... True, Nessus can help in testing signatures but IMHO, it has limitations. ... > service features in Nessus and NeWT to see what is in fact ...
    (Focus-IDS)
  • RE: Comparing the performance of two IDS products with different architectures
    ... Comparing the performance of two IDS products with different architectures ... An interesting point, “a packet is only tested for a signature when needed, and not when it isn't ... and only tests signatures that apply to those contents. ... could argue all day long about the strengths and weaknesses of “pattern matching” vs “protocol ...
    (Focus-IDS)
  • Re: How to choose an IDS/FW MSS provider
    ... > people's IDS technologies, their opaqueness drives a constant nagging ... not becuase your signatures are open. ... NFR is not a free ... >> Senior Systems Engineer ...
    (Focus-IDS)