Re: Network hardware IPS

From: Andy Cuff [Talisker] (lists_at_securitywizardry.com)
Date: 09/29/03

  • Next message: JAVIER OTERO: "RE: Network hardware IPS"
    To: "Alvin Wong" <alvin.wong@b2b.com.my>, <focus-ids@securityfocus.com>
    Date: Mon, 29 Sep 2003 19:00:02 +0100
    
    

    Hi Alvin,
    You may want to check out the salient details I collated for all the IPS
    (Inline IDS) some time ago. As far as I know it's still current though they
    seem a little thin on the ground
    http://www.networkintrusion.co.uk/inline.htm

    Hogwash - Is this still current?
    Inline_Snort - Not sure if I found the official Home page
    Intrushield
    OneSecure - The site seems to be down (bites tongue about IPS)
    RealSecure Guard - First one I played with
    UnityOne
    BorderGuard

    I'm hoping some of the spotters or even Vendors (I'm not proud) can
    highlight some that I'm missing. If you hear of any please let me know!
    take care
    -andy
    Talisker Security Tools Directory
    http://www.securitywizardry.com
    ----- Original Message -----
    From: "Alvin Wong" <alvin.wong@b2b.com.my>
    To: <focus-ids@securityfocus.com>
    Sent: Monday, September 29, 2003 9:30 AM
    Subject: Network hardware IPS

    > Hi,
    >
    > I'm interested to find out if anyone can share their experiences or
    > recommend a network hardware IPS that is deployed in front of the
    > gateway which is able to detect attack signatures and at the same time,
    > actively blocking out these attacks, alerting me in the process.
    >
    > This would be different from a passive IDS which depends on correlating
    > the logs every time an alert pops up. An ideal solution would be to be
    > able to detect the patterns and prevent them automatically, can a
    > network IPS do this?
    >
    > I understand that it is possible in some IDS to do a TCP reset after one
    > had confirmed that the connection is not acceptable, can anyone explain
    > whether an IDS that can do this be actually "active" as opposed to
    > passive?
    >
    > It would also be interesting if there could be some amount of trend
    > analysis built in which can review the destination/source ip traffic
    > over time, which can be used to identify particular boxes which are
    > easily targeted, which would mean that more work needs to be done for
    > that box.
    >
    > Regards,
    > Alvin
    >
    >
    >
    > --------------------------------------------------------------------------
    -
    > Captus Networks IPS 4000
    > Intrusion Prevention and Traffic Shaping Technology to:
    > - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
    > - Automatically Control P2P, IM and Spam Traffic
    > - Precisely Define and Implement Network Security & Performance Policies
    > FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    > http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
    > --------------------------------------------------------------------------
    -
    >

    ---------------------------------------------------------------------------
    Captus Networks IPS 4000
    Intrusion Prevention and Traffic Shaping Technology to:
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Precisely Define and Implement Network Security & Performance Policies
    FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
    ---------------------------------------------------------------------------


  • Next message: JAVIER OTERO: "RE: Network hardware IPS"

    Relevant Pages

    • RE: Recent Gartner IDS/IPS report
      ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... combinations that operating systems and applications respond improperly ... IDS alerts / second - Correlation - Virtualization ... any IPS has to do IDS first. ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... If you take a proper IPS, and by that I don't mean an IDS that has been ... followed by rate limiting and Layer 4 checks before it ...
      (Focus-IDS)
    • RE: Intrusion Prevention Systems
      ... It seems were calling an reactive IDS and IPS. ... In reality, BlackICE Guard ... IPS is hardly a "test lab device" or unproven technology. ...
      (Focus-IDS)
    • RE: IDS evaluations procedures
      ... An example would be to use an IPS to force all HTTP requests to have the host header www.xyz.com this will stop a significant proportion of HTTP noise before signature matching. ... Conversely with IDS you just don’t have the ability to white list traffic in this way, I guess you could RST any request that didn’t match the URL but I think fragmented buffer overflows and the like could sneak through - so it’s risky. ... Traffic-based anomalies? ... Are you only interested in classic "attacks" (fire up Nessus, ...
      (Focus-IDS)

  • Quantcast