RE: Traffic Balancing on High-speed IDS

kgeorgiades_at_toplayer.com
Date: 07/23/03

  • Next message: Levinson, Karl: "RE: Windows Open source/Freeware security tools"
    To: rgraham@iss.net, christian@whoop.org, focus-ids@securityfocus.com
    Date: Wed, 23 Jul 2003 11:55:43 -0400
    
    

     The cleaner, most economical and easier way to do this is to use an IDS
    Balancer (such as the Top Layer IDS Balancer).

    It will save you money on the numnber of sensors that you need to use, you
    can get redundancy on the IDS (if one IDS fails, the balancer will
    distribute the traffic to the rest in the group), and the balancer will also
    handle asymmetric flows.

    Ken Georgiades

    -----Original Message-----
    From: Graham, Robert (ISS Atlanta)
    To: Christian Kreibich; Focus IDS
    Sent: 7/22/03 2:30 PM
    Subject: RE: Traffic Balancing on High-speed IDS

    The Symantec ManHunt and ISS Proventia 1204 have that XOR feature
    built-in. For example, you can buy 4 Proventia boxes and hook them to 4
    gigabit links.

    Why this is different than 4 individual (non-teamed) sensors is when
    those 4 links carry the same traffic, so a TCP packet in a connection
    might arrive on any of the 4 interfaces. If you don't sniff all 4
    networks with each box (then do the XOR trick), then you'll drop packets
    in the middle of the connection.

    (Proventia is the ISS RealSecure appliance, the model number 1204 means
    it does 1.2 gbps across 4 interfaces).

    -----Original Message-----
    From: Christian Kreibich [mailto:christian@whoop.org]
    Sent: Monday, July 21, 2003 10:54 AM
    To: Focus IDS
    Subject: Re: Traffic Balancing on High-speed IDS

    Hi,

    On Thu, 2003-07-17 at 15:59, Thiago Mello wrote:
    > Hi,
    >
    > Im developing a IDS based on Sensor for High-Speed Networks, and Im
    > reading some paper about distributing the traffic for IDS sensors.
    >
    > I want of you some opinions on how the best way to distribute the
    > traffic to the sensors, and distribute guaranteeing the attacks, such
    as
    > DDoS. Some links, papers, are also welcome.

    look for papers on monitoring of high-speed networks. You want a scheme
    that stripes the flows across your sensors, making sure that each flow
    is kept intact -- n-valued hash functions, based for example on XORs of
    IP addresses come to mind. You can sometimes push the resulting filters
    down into the firmware of the card so you don't pollute the PCI buses on
    the sensors. Hth.

    http://citeseer.nj.nec.com/565810.html
    http://www.ist-scampi.org/publications/deliverables/D0.1.pdf

    The second one also mentions TopLayer's product.

    Cheers,
    Christian.

    -- 
    ________________________________________________________________________
                                                        http://www.whoop.org
    ------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Levinson, Karl: "RE: Windows Open source/Freeware security tools"

    Relevant Pages

    • RE: IDS on a load balanced BGP network
      ... If you take SPAN ports from your two routers and run them back into one of ... passing it to the IDS. ... taps, asymmetrically routed networks etc.), and the balancer will organise ... "Perfecting the Art of Network Security" ...
      (Focus-IDS)
    • Re: IDS deployment outside FW?
      ... your IDS sensors should never be active on the ... network that they are monitoring (unless you're doing some sort of ... able to craft the monitoring rules to focus on those devices. ...
      (Focus-IDS)
    • Re: Question on resources needed to manage IDSes
      ... The number of sensors isn't as important as the organization's required ... In that particular NOC there were about a dozen IDS sensors ... Question on resources needed to manage IDSes ... > Has any one of you seen any data on how many analysts are ...
      (Focus-IDS)
    • Re: high-speed NIDS (>1.7GBit/sec traffic) required.
      ... However it depends on the network. ... Cisco: I have not used your IDS product in years is the regex on custom rules still very limited? ... > tailoring which type of traffic different sensors see. ...
      (Focus-IDS)
    • Re: IDS event filtering
      ... > I am wanting to get an idea of what you guys out there filter from your ... > IDS sensors. ... Some of the sensors I monitor get TONS of events for MSSQL ... > have any SQL services on the internet, is it safe to filter out those ...
      (Focus-IDS)