Re: AW: Gateway IDS

From: Frank Knobbe (fknobbe@knobbeits.com)
Date: 06/28/02


From: Frank Knobbe <fknobbe@knobbeits.com>
To: Jochen Vogel <jvogel@it-sec.de>
Date: 27 Jun 2002 23:48:14 -0500


On Thu, 2002-06-27 at 03:31, Jochen Vogel wrote:
> thx for your replies,
>
> i seems there is a great interesst.
>
> i will look at hogwash and ianīs project.
>
> onsecure seems to be good too.
>
> To send RST packets or blocking the SRC IP over OPSEC
> is not really good because to bypass the system about
> latency or IP stack modifying additional IP blocking
> can end in DOS if i spoof bad packets with your partners
> source. the only way is:

Yeah, for blind blocking that is correct. When I wrote SnortSam, I tried
to include countermeasures that can reduce the risk of DoS' (white-list,
rollback support). You are correct, though. Blocking (or sniping
sessions) is not for the faint of heart. You need to know your network
well.

On the other hand, you can shoot yourself in the foot with GIDS like
Hogwash as well. For example, most shell code signatures snort has are
often triggered falsely. One annoying one was the RCPT TO overflow
signature. While that may just be annoying for an IDS that only alerts,
a GIDS would not pass that packet through and you would miss out on
legitimate traffic. False positives in GIDS take on a different
dimension.

Regards,
Frank






Relevant Pages

  • Cant access a site from Masqueraded host
    ... I'm trying to understand why I can't access a host from my NAT network. ... I thought my firewall must be blocking. ... I assume that they are blocking some packets and also maybe blocking my NAT'ed packets. ... Chain INPUT target prot opt source destination ...
    (Debian-User)
  • Re: firewall and UDP packets, and errocode 10004
    ... I tried using blocking and non-blocking sockets and the problem still ... Arkady Frenkel wrote: ... MSAFD TCPIP TCP/IP ... I have an application that sends UDP packets. ...
    (microsoft.public.win32.programmer.networks)
  • Re: Linux equivalent for ioctlsocket(FIONREAD) on datagram sockets
    ... Imagine that fast CPU sends a burst of UDP ... spirit of UDP standard should do in that particular case? ... blocking a clling thread until the NIC hardware ... reads one or more packets from socket's send buffer freeing up space ...
    (comp.os.linux.development.apps)
  • Re: dnsspoofing..
    ... >>type of attacks in local area network?? ... > You could start blocking all the packets that come or go to ... ok but dnspoofing from the same lan works and blocking ip address is not ...
    (comp.os.linux.security)