Re: Signatures taking down network



There are many parameters involved for bringing up
such situation.

1. Firstly, yes Signature QA testing might have
skipped or problems found during testing might have
been ignored due to severity of threat for which the
signatures were created in that release.

2. Testing might have happened on different product
from the one which you are using. Coz when
signature(s) for a newly discovered critical
vulnerability are added and due to pressure of
deilvering the signature pack super fast, its not
always feasible to test same signature pack against
20different products/versions.

3. Vendor might have used different test environment
for testing. For example, vendors might have tested
the signature pack by configuring a dummy network on
IDS/IPS running 2-3domains. But in live environment
you might have few 100s of different domains
configured.

4. Vendor might have tested the signatures just for
accuracy/syntax/working/attack blocking and might have
skipped the performance testing of IPS after including
new signatures with older set.

There could be many more reasons....And its not the
case of "xxx" vendor, these problems can be with any
IPS vendor. But ofcourse its a serious problem and
vendors should pay high attention to QA rather than
increasing the signature count. Coz no one would like
to make his/her machine secure by plugging out the
network cable.

-Dhruv


--- David Williams <dwilliamsd@xxxxxxxxx> wrote:

> I'm evaluating a Tipping Point box and after
> gettting the latest
> signatures I'm having problems with the box
> "crashing". My goal is
> not to bash Tipping Point, but instead to gather
> information on how
> often people have seen this type of thing among IPS
> boxes.
>
> Is there a trend with vendors to roll out signatures
> as fast as
> possible without proper QA? This brings up a lot of
> questions about
> deploying IPS. I want two opposite things from my
> vendors: 1) I want
> the latest signatures super fast. 2) I want proper
> QA so that it
> doesn't bring down my network. I realize those two
> things are
> contradictory, but I thought I'd throw it out there
> to see if anybody
> had any thoughts.
>
> thanks,
>
> d
>
>
------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to
>
http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
> to learn more.
>
------------------------------------------------------------------------
>
>


__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • RE: Signatures taking down network
    ... We've been running a TippingPoint IPS for over a year now without a single ... hours and died immediately after installing the latest signatures. ... connected the management interface to one of the same network segments it was ... connected the management interface there and it ran without problems. ...
    (Focus-IDS)
  • Re: ROI (ROSI?) on IDP devices
    ... vulnerabilities go all the way up the application stack. ... after 2 to 7 days by IPS vendor. ... I'd say that's a useless IDP system, ... The signatures are lagging too far behind the vulnerabilities. ...
    (Focus-IDS)
  • Re: IPS Implementaion
    ... Moving from an IDS centric world to the IPS side is always a big ... If your vendor differentiates between exploit and vulnerability based ... signatures, go ahead and enable the exploit signatures as they typically ... Test Your IDS ...
    (Focus-IDS)
  • Re: ROI on IDS/IPS products
    ... since an IPS is nothing more than an IDS that can drop traffic;-) ... By purchasing an IPS from a vendor and enabling even *some* of the signatures for blocking I have established that I trust my vendor and I trust the signature authors to write signatures that are good enough to block an exploit or an attempt to exploit a vulnerability. ...
    (Focus-IDS)
  • Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3
    ... You could make it require a pair of signatures, one from the vendor, ... and I thought losing a microsoft "certificate of authenticity" and ...
    (Linux-Kernel)