RE: encrypted data honeypots and IDS

From: dissolved (dissolved_at_comcast.net)
Date: 02/25/05

  • Next message: RightroundB_at_aol.com: "Good Book for Win XP /NT Administration"
    To: "'John Galt'" <everbeeninlove@gmail.com>
    Date: Thu, 24 Feb 2005 19:43:33 -0500
    
    

    Unless 75% of your traffic is encrypted, I wouldn't worry about it. We wont
    see full time encrypted networks for a while due to obvious reasons.
    When/if IPv6 ever comes out, that could be a different story

    -----Original Message-----
    From: John Galt [mailto:everbeeninlove@gmail.com]
    Sent: Monday, February 21, 2005 7:34 AM
    To: honeypots@securityfocus.com; focus-ids@securityfocus.com;
    security-basics@securityfocus.com
    Subject: encrypted data honeypots and IDS

    Hello! I have been working with IDS's and honeypots for a while, and
    have constantly been intruiged by one thing: As long as you control
    networks, its good to have all traffic encrypted (whether its over
    http over ssl or ssh instead of telnet etc), but to sniff and analyse
    data as in an IDS, you need it to be unencrypted. With encryption
    being used increasingly in so many communications, will that result in
    the demise of IDSs in the long run, unless they change their
    architecture in some manner.

    As an example, snort flags logs whenever there is a return id for
    root, since it assumes thats an automated script. But something like
    that over ssh would never get caught.

    Would be glad if anyone can give any inputs regarding work done to
    deal with this "problem"

    regards

    John Galt


  • Next message: RightroundB_at_aol.com: "Good Book for Win XP /NT Administration"

    Relevant Pages

    • Re: Need some information on HIDS!
      ... I have already invoked such a scenario in some of my previous IDS ... what I had in mind is that sniffing local data should be done in the IP ... stack after it's been dealt with by the encryption layer. ... Maybe SSH was not the best ...
      (Focus-IDS)
    • Re: [fw-wiz] Communication Device Protocols from External router directthrough Firewall
      ... TACACS is not. ... will get to SSH in a second)? ... or ACS should be on a DMZ ... Im sorry but why would you even say this as encryption between the firewall ...
      (Firewall-Wizards)
    • RE: Building the Perfect IDS - blacklisting
      ... authenticate a packet than it does to generate a bogus packet, ... the DoS flood. ... Building the Perfect IDS - blacklisting ... one word: encryption. ...
      (Focus-IDS)
    • Re: Encryption of printer files
      ... You have hit on one of the under-mentioned aspects of security. ... CUPS seems to have some encryption capability. ... through an SSH session. ... there is web-server based printing. ...
      (comp.unix.sco.misc)
    • Re: Is it legal to serve up HTML pages through SSL to all??
      ... >> if you have a question related to ssh please post it. ... > Sorry if I posted to the wrong newsgroup. ... OpenSSL libraries for SSH and the simple fact that it is encryption. ... generate your own keys dynamically and avoid their decryption keys. ...
      (comp.security.ssh)