RE: ssh and ids

From: Wozny, Scott (US - New York) (swozny_at_deloitte.com)
Date: 06/21/04

  • Next message: Adam Baldwin: "Re: possible causes of source and destination ip from external network"
    Date: Mon, 21 Jun 2004 10:47:41 -0400
    To: "Runion Mark A FGA DOIM WEBMASTER(ctr)" <mark.runion@us.army.mil>, <focus-ids@securityfocus.com>
    
    

    This has long been a conundrum within the IDS world. How can you
    inspect the contents of encrypted traffic? If you can, then your
    encryption algorithm is broken and you may as well not be using
    encryption. If you can't, then there are potential attacks that you're
    missing hiding within. When I was selling IDS the stock answer we gave
    is, "that's what host based IDS is for". Not an all encompassing
    answer, but it does lend itself to the "defense in depth" principle. I
    would suggest installing HIDS on nodes based upon likelihood of
    compromise. It's not cost effective to do them all, but if you know the
    systems on your network you should be able to figure out which are the
    most interesting to hackers. Basically the two factors to consider are
    how easy the box is to get to (i.e. how close to the Internet) and how
    valuable the information contained on the box is (i.e. does it contain
    payroll data or trade secrets). When choosing a HIDS solution you
    should keep in mind both the power of the HIDS itself in what it can
    detect AND it's ability to integrate with the data produced by your
    NIDS. If you've not already purchased / developed a correlation tool
    then seriously considering adding one to your SOC unless your existing
    NIDS vendor has both a powerful HIDS and good correlation tools built
    in. If you don't then you're likely to go bug eyed bouncing from
    console to console.

    Hope this helps...

    Scott
    -----Original Message-----
    From: Runion Mark A FGA DOIM WEBMASTER(ctr)
    [mailto:mark.runion@us.army.mil]
    Sent: Friday, June 18, 2004 2:19 PM
    To: focus-ids@securityfocus.com
    Subject: ssh and ids

    Lets suppose the attacker is mildly sophisticated, and after making the
    initial assault roots the box and installs a secure backdoor or two. Is
    there any IDS capable of isolating data it cannot read, except to
    monitor
    authorized port usage of a system or group of systems? Not to
    complicate
    the question, but when the attacker is using portal gates and all
    communications traffic is encrypted in normal channels how can an IDS
    participate? Monitoring normal traffic patterns seems a bit slow for
    detection.

    -
    Mark Runion

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law.  If you are not the intended recipient, you should delete this message.  Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited.
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Adam Baldwin: "Re: possible causes of source and destination ip from external network"

    Relevant Pages

    • RE: ssh and ids
      ... It sounds like what you are looking for is an IPS. ... An IDS is not meant to ... but when the attacker is using portal gates ... That's the entire purpose of encryption. ...
      (Focus-IDS)
    • RE: Building the Perfect IDS - blacklisting
      ... authenticate a packet than it does to generate a bogus packet, ... the DoS flood. ... Building the Perfect IDS - blacklisting ... one word: encryption. ...
      (Focus-IDS)
    • RE: IPSec and IDS
      ... HIDS you implement. ... encryption, which means it will have the same problem as your standard ... There is at least one IDS product that offers to do decryption of SSL ... > I know there is an issue with VPNs running IPSec. ...
      (Focus-IDS)
    • RE: ssh and ids
      ... box is the termination point of the SSL tunnel. ... Subject: ssh and ids ... Your claim is only partially true Peter. ... Encryption remains the bane of network-based intrusion ...
      (Focus-IDS)
    • RE: ids inquisition
      ... Dozens of IDS companies out there are merketing millions of dollars ... worth of contracts consisting of NIDS and HIDS solutions, ... from an IDS perspective are at a network layer where encryption is not ...
      (Focus-IDS)