Re: Obfuscated web pages



Are any current network based IDS/P systems able to unwind
obfuscated web script to examine the final javascript product?

Others have noted that this isn't often attempted, but it should also be mentioned that it *can't* be done generically for links of any significant bandwidth. If the unwinding routine takes a tenth of a second to run on a fast modern processor the web-browser user won't notice at all. Your IDS, on the other hand, will fall over at 10 packets/second. As processors get faster, attackers will use more complex unwinding routines to ensure the CPU load is prohibitive for an IDS.

Without this capability, it would seem that network based
IDS/IPS is destined to digress to AV style malware
signatures for malicious web server issues and that the only
reliable place to do IDS/P would be on the host.

As others have noted, both A/V and IDS are signature based detection mechanisms, so that issue exists independent of the obfuscation/unwinding issue.

Thanks,
Mike Lococo

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more.
------------------------------------------------------------------------



Relevant Pages

  • RE: interesting paper on testing sig-based IDS
    ... to evasion (the actual evasion techniques are not ... interesting paper on testing sig-based IDS ... The mutation engine applies one or more mutant operators to ... > Find out quickly and easily by testing it with real-world attacks from ...
    (Focus-IDS)
  • RE: IDS alerts / second - Correlation - Virtualization
    ... any IPS has to do IDS first. ... >assumes that your server is vulnerable against xyz and blocks it. ... >with real-world attacks from CORE IMPACT. ...
    (Focus-IDS)
  • RE: IDS event filtering
    ... The trick with IDS and SIM is to find an approach, ... Filtering is not only about yes and no, ... My experience shows that management report should include also a summary ... > Find out quickly and easily by testing it with real-world attacks from ...
    (Focus-IDS)
  • RE: Hi, I want to study IPS
    ... I think testing with dataset from place like Lincoln labs is still useful ... you will need data from real networks to test ... The lab data also will not provide any real test for an IDS beyond very ... Find out quickly and easily by testing it with real-world attacks from CORE ...
    (Focus-IDS)
  • Re: Firewalls (was Re: IDS evaluations procedures)
    ... aims of security vendors over the last few years has been minimising ... One of the reasons that the reputation of IDS suffered (and maybe why ... I suggest we drop IPS from the nomenclature. ... > with real-world attacks from CORE IMPACT. ...
    (Focus-IDS)

Quantcast