Re: IDS VS. IPS: Which is Better???

atarata_at_internode.on.net
Date: 07/05/04

  • Next message: Anton A. Chuvakin: "Re: Are sophisticated attacks just FUD?"
    To: "NAVTEJ KOHLI" <tonavtejkohli@hotmail.com>
    Date: Mon, 05 Jul 2004 17:28:12 +0950
    
    

    Hi NAVTEJ,

    IDS = Intrusion Detection System
    IPS = Intrusion Prevention System

    Now basically an IDS system just reports intrusion attacks
    where the IPS not only reports intrusion attacks it can also
    take preventive measures (blocking ports, running scripts,
    etc) and counter the instrusion attacks. The choice is
    really up to you and what your organisation needs / affords.
    What I can recommend is this:

    - IDS:
    1) An affordable solution but a good one is (for a Windows
    based network, their next version of the product will
    include *nix as well) - GFI Security Event Log Monitor
    (http://www.gfi.com)
    2) A more expensive but more comprehensive solution (for a
    mixed environment) - NetIQ Security manager
    (http://www.netiq.com)

    - IPS (for a mixed Windows and *nix network) - Stonegate
    (http://www.stonesoft.com/products/StoneGate/)

    For more technical details for these products just look on
    the sites as they are pretty good in covering the technical
    bits and pieces.

    Hope this helps.

    Cheers,
    Alex T

    > Hi , I’m new in this group. I got one project to
    implement
    > IDS on big originations. Now I have to gives one
    > presentation on IDS Vs IPS. I don’t know what is the
    > exactly difference between IDS and IPS. How IPS is good
    > then IDS.
    >
    >
    > It would be very nice of you if anyone can give me some
    > technical hints like
    > • How to start with the preparation?
    > • Which Books/Question Banks/Related Documents to
    > refer? • Any web sites/hyper links which could be
    > helpful?
    >
    >
    > I would be really thankful if you can take some precious
    > time from your busy schedule and help me out as I need it
    > very badly. Hoping for a reply soon from your side.
    >
    >
    > Regards,
    >
    > NAVTEJ KOHLI
    >
    > __________________________________________________________
    > _______ Protect your PC - get McAfee.com VirusScan Online
    >
    http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963
    >
    >
    > ----------------------------------------------------------
    > -----------------
    >
    > ----------------------------------------------------------
    > -----------------
    >

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Anton A. Chuvakin: "Re: Are sophisticated attacks just FUD?"

    Relevant Pages

    • RE: Recent Gartner IDS/IPS report
      ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... combinations that operating systems and applications respond improperly ... IDS alerts / second - Correlation - Virtualization ... any IPS has to do IDS first. ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... If you take a proper IPS, and by that I don't mean an IDS that has been ... followed by rate limiting and Layer 4 checks before it ...
      (Focus-IDS)
    • RE: Intrusion Prevention Systems
      ... It seems were calling an reactive IDS and IPS. ... In reality, BlackICE Guard ... IPS is hardly a "test lab device" or unproven technology. ...
      (Focus-IDS)
    • RE: IDS evaluations procedures
      ... An example would be to use an IPS to force all HTTP requests to have the host header www.xyz.com this will stop a significant proportion of HTTP noise before signature matching. ... Conversely with IDS you just don’t have the ability to white list traffic in this way, I guess you could RST any request that didn’t match the URL but I think fragmented buffer overflows and the like could sneak through - so it’s risky. ... Traffic-based anomalies? ... Are you only interested in classic "attacks" (fire up Nessus, ...
      (Focus-IDS)

    Loading