R: host-based ids evaluation

From: Gianpiero Porchia (gianpiero.porchia@atsweb.it)
Date: 08/19/02


From: "Gianpiero Porchia" <gianpiero.porchia@atsweb.it>
To: "IDS Focus" <focus-ids@securityfocus.com>
Date: Mon, 19 Aug 2002 12:58:19 +0200

Detmar wrote:
>Sorry, but you're off topic.
>We are discussing __host__-based ids.
>NFR NID is a network IDS.

Ok, you are right, the NID is a network IDS, and is out of this topic.
But, I've posted my last mail, only to show how you can look for strange
service on your boxes. Since I believe that a stack based IDS is a subset of
an HIDS, I think that we can detect netcat using a network traffic analyzer,
when there isn't an HIDS that looks at netstat output.
The netstat solution, IMHO is fine, but I think there are problems with that
you are looking for, example if you are looking for the executable name,
this name can be changed. But if u are looking for TCP (or UDP) ports that
shouldn't be open, we are looking for the same solution, by network level
(network traffic), and by kernel level (bound ports). The former is more
active, because detect the netcat server only when there are comms, the
latter is more proactive, because can detect the server even without comms.

Bye

- gianpiero

Ing. Gianpiero Porchia
Security Engineer
ATS - Advanced Telecom Systems
Designing, Testing, Managing Network Quality

Via Salgari, 17 - 41100 Modena - ITALY
Tel +39 059 821332
Fax +39 059 821492
E-mail: gianpiero.porchia@atsweb.it
Web site: http://www.atsweb.it



Relevant Pages

  • Re: Network IDS
    ... There are loads of network IDS out there that meet your requirements, ... All the NIDS ... > Currently I have been looking at the Symantec Gateway Device. ...
    (Security-Basics)
  • Re: Anomaly Based Network IDS
    ... Subject: Anomaly Based Network IDS ... > the network traffic and identifying anomalies on the norm, rather than relying on a specific external ... They can detect attacks ...
    (Focus-IDS)
  • Re: Anomaly Based Network IDS
    ... My company uses Lancope's StealthWatch for anomaly based network IDS. ... are quite pleased with its ability to detect zero-day undocumented attacks ...
    (Focus-IDS)
  • Re: TDD: Test-Driven Design or Test-Driven Development?
    ... >and all other deployment activities like building/modifying the comms ... >network, installing the a/c in the new computer center, configuring ...
    (comp.object)
  • Reboot and must remove and rebuild ent0 help?
    ... Here's a strange one I cannot seem to put my finger on. ... reboots when the system comes back up and tcpip is running our network ... comms still doen't work. ... followed by redefining the ent0 device and adding the gate and way ...
    (comp.unix.aix)