encrypted data honeypots and IDS

From: John Galt (everbeeninlove_at_gmail.com)
Date: 02/21/05

  • Next message: Eduardo Kienetz: "Re: New to this: How to map network?"
    Date: Mon, 21 Feb 2005 18:04:24 +0530
    To: honeypots@securityfocus.com, focus-ids@securityfocus.com, security-basics@securityfocus.com
    
    

    Hello! I have been working with IDS's and honeypots for a while, and
    have constantly been intruiged by one thing: As long as you control
    networks, its good to have all traffic encrypted (whether its over
    http over ssl or ssh instead of telnet etc), but to sniff and analyse
    data as in an IDS, you need it to be unencrypted. With encryption
    being used increasingly in so many communications, will that result in
    the demise of IDSs in the long run, unless they change their
    architecture in some manner.

    As an example, snort flags logs whenever there is a return id for
    root, since it assumes thats an automated script. But something like
    that over ssh would never get caught.

    Would be glad if anyone can give any inputs regarding work done to
    deal with this "problem"

    regards

    John Galt


  • Next message: Eduardo Kienetz: "Re: New to this: How to map network?"

    Relevant Pages

    • Re: SSH question
      ... control area. ... in /usr/local/etc/authorized_keys file and that enabled that user to ssh ... That way when bill ssh from host to hosta as jim, ...
      (SSH)
    • Re: SSH & typical corporate network use policies?
      ... In large (read paranoid) organizations, it is not uncommon to find very ... little 'net access. ... Telnet, SSH, FTP, and external NNTP are usually prohibited. ... Specializing in Wired and Wireless Networks ...
      (comp.security.firewalls)
    • Re: [fw-wiz] cisco ssh rate limit
      ... Have you thought about using an access control list instead for the ssh ... I am not deeply familiar with the PIX yet but I know on Cisco ... I'm thinking functionality like this ...
      (Firewall-Wizards)
    • Re: DNS Attacks
      ... networks by address and mask. ... I worked on this problem (on a Linux machine used for ssh), ... A whitelist is where you specify who you want to allow ... to deny access. ...
      (comp.os.vms)
    • Re: IPTABLES + SECURITY
      ... IMHO connect to a remote server directly for administration purposes is ... a risk because we cannot control software failures, ... SSH as other things is brakeable. ...
      (comp.os.linux.security)