RE: ssh and ids

From: Omar Herrera (oherrera_at_prodigy.net.mx)
Date: 06/19/04

  • Next message: Jose Nazario: "Re: Anomaly Based Network IDS"
    Date: Sat, 19 Jun 2004 15:31:12 -0600
    To: focus-ids@securityfocus.com
    
    

    > -----Original Message-----
    > From: Runion Mark A FGA DOIM WEBMASTER(ctr)

    > Lets suppose the attacker is mildly sophisticated, and after making
    the
    > initial assault roots the box and installs a secure backdoor or two.
    Is
    > there any IDS capable of isolating data it cannot read, except to
    monitor
    > authorized port usage of a system or group of systems? Not to
    complicate
    > the question, but when the attacker is using portal gates and all
    > communications traffic is encrypted in normal channels how can an IDS
    > participate?

    I haven't seen a product but I suppose there are, It wouldn't be too
    difficult for most applications. You would need something like a
    gateway+inline+nids. What this thing should do is kind of a man in the
    middle attack, connections to the outside would be redirected through
    and trapped by this device, then, this device will answer spoofing the
    real destination and forward all traffic through a new encrypted
    connection to the original destination.

    So, for someone connecting from your internal network to the outside,
    this client will actually connect to the IDS box, there the IDS will act
    as the SSH server, extract the data, analyze it and encrypt it again
    with another SSH connection until reaching the final destination.

    From outside to inside would be more or less the same, although some
    protocols might need some adjustments to work appropriately, for
    example, for SSL you might need to put the digital certificate on this
    box, rather than on your web server.

    > Monitoring normal traffic patterns seems a bit slow for
    > detection.
    What makes this slow is the memory to keep all traffic and statistics
    and search through it all. However, the search process should be faster
    for there would be fewer patterns to look at and the query would be less
    complicated than looking for certain strings within packets.

    The approach that I mention would be probably be much more slower.
    Actually, it would be no good having all this in place if after all the
    signatures you look for while traffic is decrypted does not match any
    predefined signature. You see, merely verifying authorized port usage
    has some important advantages after all (If you know exactly which ports
    are allowed to be used and which are not).

    Regards,

    Omar Herrera

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Jose Nazario: "Re: Anomaly Based Network IDS"

    Relevant Pages

    • User informix must be a Domain Member for ODBC Connection?
      ... My group is upgrading IDS from 9.40 to 11.50 on HPUX 11.23. ... Connection Failed: ... informix username in the original error output. ... "Domain Connections that Do Not Specify a Domain Name ...
      (comp.databases.informix)
    • RE: best ids placement?
      ... Just because an IDS doesn't have a two-way ... connection on the wire doesn't mean that it cannot be compromised by traffic ... no other network connectivity besides that tap. ... taps are NOT guarantee against attacks ...
      (Focus-IDS)
    • RE: ER failures between IDS 10.0.FC4 and IDS 10 9.40.UC5
      ... to be problematic going from 10.0.FC4 to our 9.40.UC5 server. ... ER failures between IDS 10.0.FC4 and IDS 10 9.40.UC5 ... 09:10:11 CDR connection to server lost, id 1, name ...
      (comp.databases.informix)
    • how to block connections running on non-default ports
      ... I launched a telnet connection to a remote server on Internet on port ... Neither our firewall or IDS was able to block ...
      (Security-Basics)
    • Re: Number maxim of concurrent conexions
      ... because for each socket connection a file descriptor is needed. ... Each SHM connection needs some SHM in the "message segment". ... I have a problem when in my IDS 9.40 in Linux System 32 Bytes have more ... Which is the max conexions for IDS? ...
      (comp.databases.informix)