Re: Fw: Promiscuous vs Inline IDS

From: Paul Schmehl (pauls_at_utdallas.edu)
Date: 05/06/03

  • Next message: Randy Taylor: "Re: sidestep"
    Date: Mon, 05 May 2003 17:20:00 -0500
    To: Mustapha Huneyd <mhbengal@yahoo.com>, focus-ids@securityfocus.com
    
    

    Without knowing more, it's impossible to say. What's your persistent
    throughput? What speed processor would you be using? Do you plan to use
    load balancing? What IDS will you be using? Etc., etc.

    Promiscuous mode does not affect throughput because it doesn't intrude on
    the packet stream. It "sits" beside it sniffing everything that goes by.
    You *can* experience packet loss, but that again depends on a number of
    factors.

    Inline IDS can definitely create a bottleneck because all traffic has to
    pass through it (depending on where you put it, but I'm assuming you want
    it at the ingress/egress point of your network.) You need to plan well and
    be very aware of the capability of the device you decide to use.

    --On Wednesday, April 30, 2003 04:40:37 PM +0400 Mustapha Huneyd
    <mhbengal@yahoo.com> wrote:

    >
    > I was wondering if there are tests conducted to show traffic (bottleneck)
    > patterns for both INLINE & Promiscuous IDS. Also are there tests that
    > highlight differences or similarities in capture patterns for both kinds
    > of IDS? Basically I want to know if an Inline IDS would create a
    > bottleneck in a Fast ethernet / GE network?.
    >
    > For e.g. SNORT inline vs ISS Realsecure or Cisco IDS
    >
    > Mustapha
    >
    >
    > -------------------------------------------------------------------------
    > ------ Can you respond to attacks based on attack type, severity, source
    > IP, destination IP, number of times attacked, or the time of day an attack
    > occurs? No?
    > No wonder why you're swamped with false positives!
    > Download a free 15-day trial of Border Guard and watch your false
    > positives disappear.
    >
    > http://www.securityfocus.com/StillSecure-focus-ids2
    > -------------------------------------------------------------------------
    > ------
    >

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu

    -------------------------------------------------------------------------------
    Can you respond to attacks based on attack type, severity, source IP,
    destination IP, number of times attacked, or the time of day an attack
    occurs? No?
    No wonder why you're swamped with false positives!
    Download a free 15-day trial of Border Guard and watch your false
    positives disappear.

    http://www.securityfocus.com/StillSecure-focus-ids2
    -------------------------------------------------------------------------------


  • Next message: Randy Taylor: "Re: sidestep"

    Relevant Pages

    • RE: False Positives
      ... > when no actual exploited attack has ... > when attackers attempt to overload an IDS' alert processing ... > Subject: False Positives ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • RE: Best Method(s) for signature verifcation.
      ... if the IDS is trying to be "smart" it may not listen on ports ... listening in order to get the IDS to see an attack. ... > Subject: Re: Best Methodfor signature verifcation. ... > false positives ...
      (Focus-IDS)
    • RE: False Positives
      ... There isn't an IDS system that will not report "false positives" ... tools are not actually attacking but testing, and they report an attack, ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • RE: On the definition of false positive - was: Re: location of an IPS
      ... You define false positive as an alert on something that was not actually an ... My issue is with the use of the word "attack". ... IDS are used to alert on network ... attack - you could test for false positives with false negatives ...
      (Focus-IDS)
    • IDS Assessment (was: Intrusion Prevention... probably something else at one point)
      ... scrutiny of all IDS features/technologies. ... Anomaly-type detection engines can ... weaknesses of each detection methodology (which is described in much ... attack d'jour with a cool sounding name and/or press ...
      (Focus-IDS)

  • Quantcast