Re: ssh and ids

From: Martin Roesch (roesch_at_sourcefire.com)
Date: 06/19/04

  • Next message: Peter_Schawacker_at_NAI.com: "RE: ssh and ids"
    Date: Fri, 18 Jun 2004 20:53:58 -0400
    To: "Runion Mark A FGA DOIM WEBMASTER(ctr)" <mark.runion@us.army.mil>
    
    

    Hey Mark,

    VENDOR ALERT: I'm a vendor and I'm going to talk about my technology.
    Please take my comments with an appropriate amount of sodium chloride.

    Sourcefire's RNA product is capable of isolating/identifying layer-7
    protocols (including encrypted protocols) and tracking the flows. For
    example, if you wanted to find SSH/SSL traffic that it being initiated
    from outside your network to inside, setting up a query (or automated
    reporting) is pretty trivial. Hacker busts into your network and sets
    up an SSH server, RNA picks it up and can let you know that it detected
    a new service and logs the flow data, etc. Anyway, if you're
    interested in seeing a demo or talking more, let me know.

    As far as IDS being able to do much with encrypted traffic, there's
    generally not much to do once the session goes encrypted. You can
    setup rules in a system like Snort to differentiate between "allowed"
    and "everyone else" hosts talking to machines on your network pretty
    easily (and you can query RNA's flow data for the info too).

    I know the NAI guys just released a mod to their sensors that allow
    them to do real-time SSL decryption if you're willing to escrow the
    private crypto keys on the box (shudder). There's been talk of
    implementing the same sort of thing in Snort (ala ssldump) for a while,
    but it's never come together...

           -Marty

    On Jun 18, 2004, at 2:18 PM, Runion Mark A FGA DOIM WEBMASTER(ctr)
    wrote:

    > Lets suppose the attacker is mildly sophisticated, and after making the
    > initial assault roots the box and installs a secure backdoor or two.
    > Is
    > there any IDS capable of isolating data it cannot read, except to
    > monitor
    > authorized port usage of a system or group of systems? Not to
    > complicate
    > the question, but when the attacker is using portal gates and all
    > communications traffic is encrypted in normal channels how can an IDS
    > participate? Monitoring normal traffic patterns seems a bit slow for
    > detection.
    >
    > -
    > Mark Runion
    >
    >
    > -----------------------------------------------------------------------
    > ----
    >
    > -----------------------------------------------------------------------
    > ----
    >
    >

    -- 
    Martin Roesch - Founder/CTO, Sourcefire Inc. - (410)290-1616
    Sourcefire: Intelligent Security Monitoring
    roesch@sourcefire.com - http://www.sourcefire.com
    Snort: Open Source Network IDS - http://www.snort.org
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Peter_Schawacker_at_NAI.com: "RE: ssh and ids"

    Relevant Pages

    • Re: IDS and NMS
      ... Start by designing and installing a network. ... Next, a more detailed view of the network is required, so a NMS is ... the network administrator wants to see what ... This is where integrating the IDS console into the NMS makes sense. ...
      (Focus-IDS)
    • Re: "false positive" inanity
      ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
      (Focus-IDS)
    • Re: Secure Network Design (DMZ, LAN, etc)
      ... I'd like one outside the firewall and one ... I assumed I could make the first IDS ... should I have the IDS listening on the 192.168.1.0/24 network as well (web ... >Since the whole world will need access to your web servers, ...
      (Security-Basics)
    • Re: which attacks will generate false positive or false negative?
      ... addresses of the servers on your network that are allowed to do DNS Zone ... you first install a Network IDS, snmpwalks may trigger from your network ... Matt brings up the point of alerts to things that didn't have any ... you're not sure of the best way to tune out false positives during your ...
      (Focus-IDS)
    • Re: Need some information on HIDS!
      ... I have already invoked such a scenario in some of my previous IDS ... What I had in mind is something like encrypting the whole ... network traffic, to prevent sniffing from intruders (let's say wall-to-wall ... analysing and displaying logs. ...
      (Focus-IDS)