RE: IPS vs Firewall

From: Juan Velasquez (Juan_at_EvolutionH.com)
Date: 04/28/04

  • Next message: Steven Trewick: "RE: IPS vs Firewall"
    To: <security-basics@securityfocus.com>
    Date: Tue, 27 Apr 2004 20:44:00 -1000
    
    

    I'm sorry, but can you remind me as to what IPS stands for?
    I found IDS in the dictionary of "Virtual Entity of Relevant Acronyms"
    meaning "Intrusion Detection System."

    However, IPS only brings up "InPlane Switching [technology] (LCD)," and
    "Information Processing Standards."
    I can't imagine that I have the correct meaning here.
    Searches in google also were not very helpful either.

    You seem to use the term IPS as if it's not completely equivalent to an
    IDS or a firewall and that it may be used as an alternative to either.

    Anyway, in regards to your question: "how would you go about showing
    that firewalls or BigIP routers can be attacked directly?"

    Searching in google for "cisco firewall exploits" brings up a few
    interesting links.

    -----Original Message-----
    From: Benny Late [mailto:lvmygop@hotmail.com]
    Sent: Tuesday, April 27, 2004 10:16 AM
    To: security-basics@securityfocus.com
    Subject: IPS vs Firewall

    List,

    I am to give a presentation concerning IPS vs. IDS and why we have
    decided
    to implement an IPS solution. I have stuff about each of those, but my
    big
    problem is going to come from my LAN/WAN group. Because I've decided to

    place the IPS outside the firewall, they have already moaned about it
    and I
    know they're going to bring up why we need IPS vs. Firewall. I have
    stuff
    about what firewalls don't look for or do compared to IPS.

    My question is, how would you go about showing that firewalls or BigIP
    routers can be attacked directly? For those of you concidering IPS, can
    you
    impart any of the knowledge gained by implementing your solutions?

    Many thanks,
    Benny

    _________________________________________________________________
    >From must-see cities to the best beaches, plan a getaway with the
    Spring
    Travel Guide! http://special.msn.com/local/springtravel.armx

    ------------------------------------------------------------------------

    ---
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
    off 
    any course! All of our class sizes are guaranteed to be 10 students or
    less 
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of
    in-the-field 
    pen testing experience in our state of the art hacking lab. Master the
    skills 
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
    any course! All of our class sizes are guaranteed to be 10 students or less 
    to facilitate one-on-one interaction with one of our expert instructors. 
    Attend a course taught by an expert instructor with years of in-the-field 
    pen testing experience in our state of the art hacking lab. Master the skills 
    of an Ethical Hacker to better assess the security of your organization. 
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------
    

  • Next message: Steven Trewick: "RE: IPS vs Firewall"

    Relevant Pages

    • Re: IPS in the Enterprise UTM Firewall testing results
      ... I configured them as I believe a sane IPS manager would do. ... I am fairly opposed to putting an IDS inside your firewall---I think that this is asking for trouble performance-wise---but certainly there are very different catch rates when you configure the devices as an IDS. ... My conclusion is that GENERALLY you will not want to use a UTM firewall as an IDS, because of performance and because of the specific design. ... I think you're stating the obvious here, but I will point out one important issue: we specifically asked for 1Gbit boxes, and not faster than that. ...
      (Focus-IDS)
    • RE: Recent Gartner IDS/IPS report
      ... despite what Gartner states) there is no single solution for IDS or IPS (or a ... We use a suite of tools that includes both and a firewall. ... system and it continued to stay compromised because the firewall or an IPS did ... Point being...everyone knows how to have good physical security, ...
      (Focus-IDS)
    • Re: Changes in IDS Companies?
      ... Well...Netscreen didn't *build* a NIPS, ... while everyone gets all excited about the possibility of inline IDS, ... IPS is not a performance bottleneck. ... Firewall & IDS vendors ally/acquire partners on the other side, ...
      (Focus-IDS)
    • RE: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor
      ... Cisco IPS is not simply an inline IDS. ... zero-day, or zero-hour, worm protection all by itself. ... of a firewall product, like network address translation and VPN. ... Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor ...
      (Focus-IDS)
    • RE: amount of alarms generated by IDS
      ... Inline IDS exists, it's just what you call your IPS ... will the IPS vendors usurp the firewall vendors or will the firewall ...
      (Focus-IDS)