RE: IDS event filtering
dcdave_at_att.net
Date: 01/02/05
- Previous message: Stef: "Re: IDS event filtering"
- Next in thread: Evans, Arian: "RE: IDS event filtering"
- Maybe reply: Evans, Arian: "RE: IDS event filtering"
- Maybe reply: Phil Hollows: "RE: IDS event filtering"
- Maybe reply: Ofer Shezaf: "RE: IDS event filtering"
- Maybe reply: Phil Hollows: "RE: IDS event filtering"
- Maybe reply: Phil Hollows: "RE: IDS event filtering"
- Maybe reply: Ofer Shezaf: "RE: IDS event filtering"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: "Harper, Patrick" <Patrick.Harper@phns.com>, <CraftedPacket@securitynerds.org>, <focus-ids@lists.securityfocus.com> Date: Sun, 02 Jan 2005 17:09:33 +0000
I typically want a sensor outside the firewalls and DMZs to register all attacks 'beating against the door' (within traffic limitations). Firewalls block most of the problems, and I may have a sensor somewhere inside to determine if any attack got through or around the firewall, but most non-vulnerabilities are tweaked out by threshold or by legitimate address list on the inside.
It is important to avoid tuning out real attacks when they happen by having over-pruned the inside attack tree...
dcdave
Dave Druitt
-- CSO InfoSec Group 703-626-6516 -------------- Original message ---------------------- From: "Harper, Patrick" <Patrick.Harper@phns.com> > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Thresholding is a wonderful thing. And no, I personally do not want > to see alerts on tings I do not have. If I am an all apache shop > then I do not turn on any IIS rules. I also make sure, via scanning > and vulnerability analysis, that I do not in fact have any IIS (or > whatever) installed. You first need to have a good inventory of what > you have. And you need to keep that up to date so you always know > what you have. Then you trim all rules to that. Weather it be > ingress - egress firewall rules, IDS configs, or whatever. Figure > out what you have, learn how it flows (and make it work/flow the > secure way) then monitor it. > > > - -----Original Message----- > From: Billy Dodson [mailto:CraftedPacket@securitynerds.org] > Sent: Friday, December 31, 2004 9:37 AM > To: focus-ids@lists.securityfocus.com > Subject: IDS event filtering > > I am wanting to get an idea of what you guys out there filter from > your > IDS sensors. Some of the sensors I monitor get TONS of events for > MSSQL > control overflows. If the customer is patched for slammer and does > not > have any SQL services on the internet, is it safe to filter out those > events? Do you still want to see that traffic even though you know > your > are not vulnerable? Thanks! > > - ---------------------------------------------------------------------- > - ---- > Test Your IDS > > Is your IDS deployed correctly? > Find out quickly and easily by testing it with real-world attacks > from > CORE IMPACT. > Go to > http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 > to learn more. > - ---------------------------------------------------------------------- > - ---- > > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP 8.1 > > iQA/AwUBQdXFLpiWafDb7+B/EQLkZwCgxqFePWcqpCbc4/gTEuaUJYBY6iYAoOKi > xe1e6rLpQeTIU7O+zuW96Fj1 > =SkUh > -----END PGP SIGNATURE----- > > > > > Disclaimer: > This electronic message, including any attachments, is confidential and intended > solely for use of the intended recipient(s). This message may contain > information that is privileged or otherwise protected from disclosure by > applicable law. Any unauthorized disclosure, dissemination, use or reproduction > is strictly prohibited. If you have received this message in error, please > delete it and notify the sender immediately. > > > > > -------------------------------------------------------------------------- > Test Your IDS > > Is your IDS deployed correctly? > Find out quickly and easily by testing it with real-world attacks from > CORE IMPACT. > Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 > to learn more. > -------------------------------------------------------------------------- > -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
- Previous message: Stef: "Re: IDS event filtering"
- Next in thread: Evans, Arian: "RE: IDS event filtering"
- Maybe reply: Evans, Arian: "RE: IDS event filtering"
- Maybe reply: Phil Hollows: "RE: IDS event filtering"
- Maybe reply: Ofer Shezaf: "RE: IDS event filtering"
- Maybe reply: Phil Hollows: "RE: IDS event filtering"
- Maybe reply: Phil Hollows: "RE: IDS event filtering"
- Maybe reply: Ofer Shezaf: "RE: IDS event filtering"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|