Re: ssh and ids

From: Tony Carter (tcarter_at_entrusion.com)
Date: 06/22/04

  • Next message: Shafi, Shahid: "RE: Anomaly Based Network IDS"
    Date: Mon, 21 Jun 2004 22:39:25 -0400
    To: Martin Roesch <roesch@sourcefire.com>
    
    

    Since the subject came up, I've started writing the ssldump
    preprocessor. I'll keep the list posted as I make progress and need
    some testers...

    -Tony

    On Jun 18, 2004, at 8:53 PM, Martin Roesch wrote:

    > Hey Mark,
    >
    > VENDOR ALERT: I'm a vendor and I'm going to talk about my technology.
    > Please take my comments with an appropriate amount of sodium chloride.
    >
    > Sourcefire's RNA product is capable of isolating/identifying layer-7
    > protocols (including encrypted protocols) and tracking the flows. For
    > example, if you wanted to find SSH/SSL traffic that it being initiated
    > from outside your network to inside, setting up a query (or automated
    > reporting) is pretty trivial. Hacker busts into your network and sets
    > up an SSH server, RNA picks it up and can let you know that it
    > detected a new service and logs the flow data, etc. Anyway, if you're
    > interested in seeing a demo or talking more, let me know.
    >
    > As far as IDS being able to do much with encrypted traffic, there's
    > generally not much to do once the session goes encrypted. You can
    > setup rules in a system like Snort to differentiate between "allowed"
    > and "everyone else" hosts talking to machines on your network pretty
    > easily (and you can query RNA's flow data for the info too).
    >
    > I know the NAI guys just released a mod to their sensors that allow
    > them to do real-time SSL decryption if you're willing to escrow the
    > private crypto keys on the box (shudder). There's been talk of
    > implementing the same sort of thing in Snort (ala ssldump) for a
    > while, but it's never come together...
    >
    > -Marty
    >
    >
    > On Jun 18, 2004, at 2:18 PM, Runion Mark A FGA DOIM WEBMASTER(ctr)
    > wrote:
    >
    >> Lets suppose the attacker is mildly sophisticated, and after making
    >> the
    >> initial assault roots the box and installs a secure backdoor or two.
    >> Is
    >> there any IDS capable of isolating data it cannot read, except to
    >> monitor
    >> authorized port usage of a system or group of systems? Not to
    >> complicate
    >> the question, but when the attacker is using portal gates and all
    >> communications traffic is encrypted in normal channels how can an IDS
    >> participate? Monitoring normal traffic patterns seems a bit slow for
    >> detection.
    >>
    >> -
    >> Mark Runion
    >>
    >>
    >> ----------------------------------------------------------------------
    >> -----
    >>
    >> ----------------------------------------------------------------------
    >> -----
    >>
    >>
    > --
    > Martin Roesch - Founder/CTO, Sourcefire Inc. - (410)290-1616
    > Sourcefire: Intelligent Security Monitoring
    > roesch@sourcefire.com - http://www.sourcefire.com
    > Snort: Open Source Network IDS - http://www.snort.org
    >
    >
    > -----------------------------------------------------------------------
    > ----
    >
    > -----------------------------------------------------------------------
    > ----
    >

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Shafi, Shahid: "RE: Anomaly Based Network IDS"

    Relevant Pages

    • RE: IDS testing...again [WAS: Re: (OpenBSD or Linux)]
      ... Subject: IDS testing...again ... How come vendor Y wasn't in there? ... I think the Mier tests left me with more questions then answers. ... This has been debated quite a bit on this (and other lists) in the past. ...
      (Focus-IDS)
    • RE: TippingPoint Releases Open Source Code for FirstIntrusionPrevention Test Tool, Tomahawk
      ... Oh, I have to disagree with this, and for a one-word reason: ... geared towards making any one vendor look better than all the others...well, ... > FirstIntrusionPrevention Test Tool, Tomahawk ... > much of a vendor presence as TippingPoint or any other IDS ...
      (Focus-IDS)
    • Talisker Site Returns - Rate/Review IDS Now
      ... Our vendor neutral site has been providing salient detail on every single ... Network IPS ... Application IDS ... Network Taps ...
      (Focus-IDS)
    • RE: IDS in a loadbalanced Network
      ... This is likely a vendor specific question. ... Some vendors can monitor the HSRP traffic directly, ... not be able to reliably recognize attacks tunneled within HSRP. ... all of the links to the same IDS. ...
      (Focus-IDS)
    • RE: Help in evaluating Inline IDS/IPS solution
      ... This really depends on the vendor and the signature. ... Do the IDS vendors claim this? ... support on new attacks and vulnerabilities found. ... INTRUSION PREVENTION: READY FOR PRIME TIME? ...
      (Focus-IDS)