Traffic Balancing on High-speed IDS

From: Thiago Mello (tmello_at_pop.com.br)
Date: 07/17/03

  • Next message: Levinson, Karl: "RE: auto-response IDS againt port-scanning or attacked ip?"
    To: focus-ids@securityfocus.com
    Date: 17 Jul 2003 11:59:27 -0300
    
    

    Hi,

    Im developing a IDS based on Sensor for High-Speed Networks, and Im
    reading some paper about distributing the traffic for IDS sensors.

    I want of you some opinions on how the best way to distribute the
    traffic to the sensors, and distribute guaranteeing the attacks, such as
    DDoS. Some links, papers, are also welcome.

    Thanks in advance.

    Thiago Mello

    -------------------------------------------------------------------------------
    Is your IDS deployed correctly?
    Find out by easily testing it with real-world attacks from CORE IMPACT.
    Go to www.coresecurity.com/promos/sf_eids1 to learn more.
    -------------------------------------------------------------------------------


  • Next message: Levinson, Karl: "RE: auto-response IDS againt port-scanning or attacked ip?"

    Relevant Pages

    • Re: IDS deployment outside FW?
      ... your IDS sensors should never be active on the ... network that they are monitoring (unless you're doing some sort of ... able to craft the monitoring rules to focus on those devices. ...
      (Focus-IDS)
    • Re: Question on resources needed to manage IDSes
      ... The number of sensors isn't as important as the organization's required ... In that particular NOC there were about a dozen IDS sensors ... Question on resources needed to manage IDSes ... > Has any one of you seen any data on how many analysts are ...
      (Focus-IDS)
    • Re: high-speed NIDS (>1.7GBit/sec traffic) required.
      ... However it depends on the network. ... Cisco: I have not used your IDS product in years is the regex on custom rules still very limited? ... > tailoring which type of traffic different sensors see. ...
      (Focus-IDS)
    • Re: IDS event filtering
      ... > I am wanting to get an idea of what you guys out there filter from your ... > IDS sensors. ... Some of the sensors I monitor get TONS of events for MSSQL ... > have any SQL services on the internet, is it safe to filter out those ...
      (Focus-IDS)
    • RE: Traffic Balancing on High-speed IDS
      ... most economical and easier way to do this is to use an IDS ... Balancer. ... It will save you money on the numnber of sensors that you need to use, ... Traffic Balancing on High-speed IDS ...
      (Focus-IDS)