ssh and ids

From: Runion Mark A FGA DOIM WEBMASTER(ctr) (mark.runion_at_us.army.mil)
Date: 06/18/04

  • Next message: Tom Arseneault: "RE: IDS Testing tool"
    To: focus-ids@securityfocus.com
    Date: Fri, 18 Jun 2004 18:18:54 -0000
    
    

    Lets suppose the attacker is mildly sophisticated, and after making the
    initial assault roots the box and installs a secure backdoor or two. Is
    there any IDS capable of isolating data it cannot read, except to monitor
    authorized port usage of a system or group of systems? Not to complicate
    the question, but when the attacker is using portal gates and all
    communications traffic is encrypted in normal channels how can an IDS
    participate? Monitoring normal traffic patterns seems a bit slow for
    detection.

    -
    Mark Runion

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Tom Arseneault: "RE: IDS Testing tool"

    Relevant Pages

    • RE: Active response... some thoughts.
      ... Subject: Active response... ... Netscreen IDS features TCP reset as a major feature of their ... between your attacker and your IDS, ... The attacker could modify his IP-stack such that resets are being ignored ...
      (Focus-IDS)
    • Re: Active response... some thoughts.
      ... It is good to remember that many IDS implementations send ... TCP RST to the two endpoints in the communication. ... the attacker can just simply hack his stack to igno ... stack such that resets are being ...
      (Focus-IDS)
    • Re: Active response... some thoughts.
      ... Subject: Active response... ... > drops the packet on the wire before it gets past the in-line IDS. ... Active-response is great if you have a signature for it ... the attacker can just simply hack his stack to ignore the ...
      (Focus-IDS)
    • RE: Active response... some thoughts.
      ... between your attacker and your IDS, ... of the IDS you have. ... Subject: AW: Active response... ... The attacker could modify his IP-stack such that resets are being ignored ...
      (Focus-IDS)
    • Re: Appeal for Help. NOT Code Red But Is It?
      ... our server immediately responds back to the prober ... What is happening is that the IDS is becomming confused about who the ... each worm that is still on its way from the attacker. ... > and outbound port was 2913. ...
      (Incidents)