Re: Vulnerability vs. Exploit signatures and IPS??

From: Ed Gibbs (ed_at_digitalconclave.com)
Date: 05/18/05

  • Next message: Jordan Wiens: "Re: Vulnerability vs. Exploit signatures and IPS??"
    To: "Jacob Winston" <jctx09@yahoo.com>, <focus-ids@securityfocus.com>
    Date: Wed, 18 May 2005 13:00:54 -0700
    
    

    Jacob,

    Vulnerabilities are the flaw, while an exploit is what takes advantage of
    the vulnerability.

    For example, Blaster. The vulnerability was in Microsoft's DCE RPC code,
    while "Blaster" was the name of the exploit that took advantage of the flaw
    in the code. When Blaster first hit the net, signature writers were
    scrambling to develop a signature that would detect it, but kept producing
    signatures for the exploit, which kept changing, and therefore new
    signatures were coming out (some as high as 16 different signatures).

    TippingPoint is correct in their assertion that writing signatures for the
    vulnerability is better. Signatures based on exploits run into problems,
    simply because exploits have variances and can morph, which makes signatures
    based on the exploit ineffective. However, signatures based on the
    vulerability typically doesn't change.

    Ed Gibbs
    IPS Security Technologist
    ed@digitalconclave.com

    Exploit
    ----- Original Message -----
    From: "Jacob Winston" <jctx09@yahoo.com>
    To: <focus-ids@securityfocus.com>
    Sent: Monday, May 16, 2005 7:57 PM
    Subject: Vulnerability vs. Exploit signatures and IPS??

    Can someone explain to me the difference in writing signatures based on
    Vulnerabilities versus writing signatures based on Exploits? TippingPoint
    makes a claim that their IPS is better because they write signatures based
    on Vulnerabilities and not exploits. I don't quite understand this.

    Thank you,

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Jordan Wiens: "Re: Vulnerability vs. Exploit signatures and IPS??"

    Relevant Pages

    • Re: Snort and Nessus Signature
      ... >> information for many of the snort signatures (CVE, BID, descriptions, ... we have found that there can be multiple CVE entries ... > exploitation of a vulnerability not an exploit. ... > bugtraq reference: 1565 ...
      (Focus-IDS)
    • RE: Vulnerability & Exploit Signatures
      ... | Subject: Re: Vulnerability & Exploit Signatures ... companies who have built security "appliances", web interfaces on top of ... does make for an easier way to kick start your own security company. ... Obviously to sit down and truly write your own IDS/IPS and Vulnerability ...
      (Focus-IDS)
    • RE: IDS vs. IPS deployment feedback
      ... the vulnerability was initially announced, the SNORT community (I do not ... know which exact group created these signatures) added approximately 300 ... SNORT engine itself, ...
      (Focus-IDS)
    • Re: Article on WebDAV Vulnerability (MS03-007)
      ... >> Vulnerability, ... the reference to ISS for signatures to detect this exploit, ... With the WebDAV patch alone, ... there is a detection rule from the Nessus website. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Article on WebDAV Vulnerability (MS03-007)
      ... >> Vulnerability, ... the reference to ISS for signatures to detect this exploit, ... With the WebDAV patch alone, ... there is a detection rule from the Nessus website. ...
      (microsoft.public.win2000.security)