Re: definition for Inline IDS/IPS

From: Ravi Kumar (ravivsn_at_rocsys.com)
Date: 09/27/04

  • Next message: Jeremy Gonzales: "Snort"
    Date: Tue, 28 Sep 2004 01:02:01 +0530 (IST)
    To: <vijaik@ctd.hcltech.com>
    
    

    Vijai,

    IDS are of two types- HIDS( Host Intrusion detection system) and NIDS(
    Network Intrusion detection system)

    IDS combined with firewall is IPS( Intrusion prevention system). IPS not
    only detects attacks but prevents them.

    IPS is said to be IIPS if it operates inline. In the sense, it takes in
    each and every packet that comes to the network under prevention.

    Prevention is done by closing away the connections with TCP Resets in case
    of TCP and ICMP destination unreachable in case of UDP connections and
    terminationg the state in the firewall.

    IIPS is more advantageous than sniffer mode IDS as it does not miss a
    single packet. But the disadvantage would be risk of loss in genuine
    connections if its a false positive and performance degradation.

    Inline IDS by the name means it cannot prevent the attacks even though it
    takes in every packet.

    HTH,
    Ravi
    ROCSYS Technologies Ltd
    http://www.rocsys.com

    > Hi folks ,
    >
    > can anybody pls clarify me the functionality definition for inline
    > IDS/IPS??How it differ from normal IDS operation??
    >
    > i came to know that Inline IDS is nothing called as IPS ,am i rite.
    >
    > pls clear my doubt..
    >
    > thanx in advance
    >
    >
    >
    > Regds
    > Vijai.K
    >
    >
    >
    > DISCLAIMER
    > This message and any attachment(s) contained here are information that
    > is confidential, proprietary to HCL Technologies and its customers.
    > Contents may be privileged or otherwise protected by law. The
    > information is solely intended for the individual or the entity it is
    > addressed to. If you are not the intended recipient of this message, you
    > are not authorized to read, forward, print, retain, copy or disseminate
    > this message or any part of it. If you have received this e-mail in
    > error, please notify the sender immediately by return e-mail and delete
    > it from your computer.
    >
    >
    >
    > --------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it with real-world attacks from
    > CORE IMPACT. Go to
    > http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to
    > learn more.
    > --------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
    --------------------------------------------------------------------------


  • Next message: Jeremy Gonzales: "Snort"

    Relevant Pages

    • RE: Recent Gartner IDS/IPS report
      ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... combinations that operating systems and applications respond improperly ... IDS alerts / second - Correlation - Virtualization ... any IPS has to do IDS first. ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... If you take a proper IPS, and by that I don't mean an IDS that has been ... followed by rate limiting and Layer 4 checks before it ...
      (Focus-IDS)
    • RE: Intrusion Prevention Systems
      ... It seems were calling an reactive IDS and IPS. ... In reality, BlackICE Guard ... IPS is hardly a "test lab device" or unproven technology. ...
      (Focus-IDS)
    • RE: IDS evaluations procedures
      ... An example would be to use an IPS to force all HTTP requests to have the host header www.xyz.com this will stop a significant proportion of HTTP noise before signature matching. ... Conversely with IDS you just don’t have the ability to white list traffic in this way, I guess you could RST any request that didn’t match the URL but I think fragmented buffer overflows and the like could sneak through - so it’s risky. ... Traffic-based anomalies? ... Are you only interested in classic "attacks" (fire up Nessus, ...
      (Focus-IDS)