Re: Wishlist for IPS Products - HYBRID IPS

From: Andy Cuff (lists_at_securitywizardry.com)
Date: 09/12/04

  • Next message: David Maynor: "Re: Wishlist for IPS Products"
    To: "PS R" <secureyourself@gmail.com>, <focus-ids@securityfocus.com>
    Date: Sun, 12 Sep 2004 11:12:47 +0100
    
    

    Hey Jack,
    Great wish list and some of the vendors are moving towards much of this
    functionality. However, presently I see a divide in the technology; firstly
    rate based products which have been termed Attack Mitigation Systems and
    secondly content based products termed Intrusion Prevention Systems. As I
    mentioned earlier, many of the products focus on one or the other side of
    the divide, but increasingly offer both types of analysis in a hybrid
    fashion. Looking at your wishlist is appears you are aiming at the Hybrid
    IPS market

    I have attempted to divide the 2 camps below.
    AMS http://securitywizardry.com/idsdosmit.htm
    Network IPS http://securitywizardry.com/inline.htm
    But I haven't looked at breaking out the various Hybrid IPS, if anyone
    wishes to take this on I will create the page, though with a 5 hour daily
    commute have very little time for online researching of the products (Hence
    I've been quiet for the last few weeks)

     -andy cuff
    Talisker's Computer Security Portal
    Computer Network Defence Ltd
    http://www.securitywizardry.com
    ----- Original Message -----
    From: "PS R" <secureyourself@gmail.com>
    To: <focus-ids@securityfocus.com>
    Sent: Friday, September 10, 2004 3:18 PM
    Subject: Wishlist for IPS Products

    > I have seen a lot of discussion about the differences between IDS,
    > IPS, and firewalls and the potential for convergence, but I do not
    > recall a discussion on the primary features that an IPS should have
    > out of the box.
    >
    > I am thinking of:
    > - Flow Control - limitations on flooding, unused connections, etc...
    > - Robust, ACURATE signature base
    > - Packet capture - no debate on how much before, as that has been covered
    > - Pre-deployment network analysis tools to accelerate deployment
    > - Anomaly detection
    > - Alert export compatibility with 3rd party event management solutions
    >
    > It seems like discussions of this type can only serve to improve the
    > products on the market (or coming to the market), since we know at
    > least some of the vendors are monitoring this list.
    >
    > Jack
    >
    > --------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    > Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    > --------------------------------------------------------------------------
    >

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
    --------------------------------------------------------------------------


  • Next message: David Maynor: "Re: Wishlist for IPS Products"

    Relevant Pages

    • RE: Recent Gartner IDS/IPS report
      ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
      (Focus-IDS)
    • IPS test criteria (was IDSIPS that can handle one Gig)
      ... Chris - what makes ICSA particularly relevant when it comes to defining IPS ... Speak to the vendors who were at their recent forum meeting ... a wide range of traffic loads and packet sizes. ... wide range of test criteria). ...
      (Focus-IDS)
    • RE: NIPS Vendors explicit answer
      ... this is the only comprehensive independent IPS test that's been ... Make sure the product continues to block attacks when simple, ... Test the IPS like you would any other network element (switch, ... The other vendors waiting for my tests:) are Netscreen IDP,RealSecure ISS Proventia G200 and Network Associates NAI Intruvert 2600 series. ...
      (Focus-IDS)
    • Re: IPS Reliability/Availability
      ... switched focus from supplying firewall vendors to supplying in-line IPS ... Subject: IPS Reliability/Availability ... appliance simply by adding processor boards. ... Does anybody have a list of which vendors are using ASICs ...
      (Focus-IDS)
    • RE: IDSIPS that can handle one Gig
      ... > and defining what the IPS test standards should be - is ... >> regards to packet size, traffic mix, etc. ... >> doing pattern matching in the CPU you could run out of CPU ... >> your statement about vendors not having RAID. ...
      (Focus-IDS)