Re: Crying wolf: False alarms hide attacks : Eight IDSs fail to impressduring the monthlong test on a production network.

From: Drew (simonis@myself.com)
Date: 06/28/02


Date: Fri, 28 Jun 2002 14:26:57 -0400
From: Drew <simonis@myself.com>
To: focus-ids@securityfocus.com

Matt.Carpenter@alticor.com wrote:
>
> "Tom D'Aquino" <tom_daquino@yahoo.com>

> >>"But Opus One's servers run OpenVMS, not Windows. Even though it is
> >>trivially easy to figure out what operating system a Web server uses, not
> >>one of the IDSs did so."
>
> Yes, this might be a nice thing for an IDS to do (check the OS and Software
> when or before an attack), but that sounds an awful lot like "bad traffic"
> to me. Somehow our IDS boxes doing the very things we don't want to see on
> a network. Not to mention that in a split-responsibility environment, this
> is a political nightmare. Some NT/IIS Admin suddenly has someone else he
> can blame when s/he's asked to explain why they have to reboot their boxes
> so often. No thanks. If that is of value, make sure it is something which
> can be turned OFF, please.

This is something that Symantec's NetProwler does, but I've heard that
they are discontinuing that product. Dunno if thats a rumor or not...



Relevant Pages

  • Re: attacks: detection and respond
    ... All these, except perl, have a reasonable size. ... the main problem with IDS systems is that attacks ... documentation provided in the operating system man pages. ... users can decide if they want or not to install it. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: NIPS Vendors explicit answer
    ... If you confine your thinking to statistical anomaly detection, ... and new network behaviors. ... The value to IDS (regardless if its ipAngle, RNA/Snort, NeVO/some other ... The simplest example I can condense this to is a single web server. ...
    (Focus-IDS)
  • product reviews
    ... Subject: product reviews ... number of options for perimeter security- firewalls and IDS boxes, ... IDS ...
    (Focus-IDS)
  • Re: Newbie IDS questions
    ... Hi Mike, it sure is possible, but I would suggest using iptables on your ... to block portscans and filter traffic. ... Actualy, for an operating system / firewall / IDS, I would use FreeBSD ...
    (Focus-IDS)
  • Firewall or IDS
    ... > IIS and security hotfixes. ... > They are using Cisco PIX firwall - with some mini IDS capabilities - able ... > able to defend against application layer attacks like Code Red. ... >,etc on my web server. ...
    (Focus-Microsoft)