RE: IDS and Spywares

From: vipul kumra (vikumar2_at_yahoo.com)
Date: 10/12/05

  • Next message: Jonathan Gauntt: "Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor"
    Date: Wed, 12 Oct 2005 03:41:22 -0700 (PDT)
    To: dhruv_ymca@yahoo.com, neelabhsharma1@gmail.com, focus-ids@securityfocus.com
    
    

    Hi Dhruv,

    I agree with what you have said... but then there is
    no 100% fool proof method for detecting anything. As
    far as I've seen iPolicy Networks IDS protection is
    quite strong... :)

    Vipul Kumra
    Sr. Security Analyst

    -----Original Message-----
    From: Dhruv Soi [mailto:dhruv_ymca@yahoo.com]
    Sent: Saturday, October 08, 2005 11:20 AM
    To: neelabhsharma1@gmail.com;
    focus-ids@securityfocus.com
    Subject: Re: IDS and Spywares

    Yeah you are right. Spyware detection through any
    anti-spyware program would be stronger mechanism than
    detecting it through IDS. But installation or
    information upload attempt of spyware can be blocked
    by IDS. Blocking may be in terms of detecting the
    vulnerability exploit attempt using which spyware
    installation occurs. Like IE vulnerabilities (IE chm,
    Drag Drop etc etc), or it could be detecting unique
    CLSIDs of known Spyware programs. And there are many
    products (Tipping Point, iPolicy etc. etc.) which
    claim that they block Spyware in their IDS. But I
    don't believe that Network based Spyware detection is
    full proof protection for Spyware but still it helps
    to certain extend.

    Ciao
    Dhruv

    --- neelabhsharma1@gmail.com wrote:

    > Could anyone in the group name a few IDS which
    > detect spywares. In my view spywares are to be
    > detected by an antivirus system and not by a network
    > device.
    >
    >
    ------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it
    > with real-world attacks from CORE IMPACT.
    > Go to
    >
    http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    >
    > to learn more.
    >
    ------------------------------------------------------------------------
    >
    >

            
                    
    __________________________________
    Yahoo! Mail - PC Magazine Editors' Choice 2005
    http://mail.yahoo.com

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to
    http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708

    to learn more.
    ------------------------------------------------------------------------

                    
    __________________________________
    Yahoo! Music Unlimited
    Access over 1 million songs. Try it free.
    http://music.yahoo.com/unlimited/

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Jonathan Gauntt: "Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor"

    Relevant Pages

    • RE: IDS and Spywares
      ... I strongly disagree that IDS is not effective with spyware. ... Network based detection and BLOCKING is the most effective way I've seen ... This is layer 2, detection. ...
      (Focus-IDS)
    • detecting network crowd surges
      ... of the user IPs on an ISP's cable modem network or all of the IPs at ... to do this in realtime with firewall, network, ids, netflow, .etc ... Most of the operational stuff I've run across for detecting botnets ... different ways to manage a botnet. ...
      (Focus-IDS)
    • Re: IDS and Spywares
      ... Spyware detection through any ... detecting it through IDS. ... Blocking may be in terms of detecting the ... installation occurs. ...
      (Focus-IDS)
    • RE: IDS and Spywares
      ... Network based detection is able to deal ... hIDS/hIPS ar much more effective in detecting and preventing these attacks. ... malware with a network based IDS or IPS. ... I think this is what Dhruv meant. ...
      (Focus-IDS)
    • Re: IDS and Spywares
      ... It's not very efficient to use an application signature to scan network ... and most fundamental way to block spyware with a network ... Subject: IDS and Spywares ...
      (Focus-IDS)