Re: Any IDS Recommendations?

From: Mercury (me_at_spam.com)
Date: 07/13/05


Date: Thu, 14 Jul 2005 00:12:00 +1200

Please ignore this if your site is not a High Security site.

If you are using SSL, then where is the End Point? IE where is the encrypted
traffic decrypted?

I would expect your auditors to have a hissy fit if the SSL traffic were
dencrypted anywhere sniffable, snortable or IDS'able as that could lead to
identity theft.

For a high security site, logging SSL traffic is pointless, logging source
ip, port, time is more useful. Logging decrypted SSL traffic is an outright
danger.

I am happy to be corrected if needs be.

"The Poster" <nospam@nospam_dontyoudare.net> wrote in message
news:uTuR$k4hFHA.2644@TK2MSFTNGP09.phx.gbl...
> G/Day Forum,
>
> I currently in the process of evaluating a number of IDS solutions. This
> IDS
> system will sit between an edge router (configured with ingress/egress
> filtering) and a Cisco Firewall. Our throughput requirement is low, as
> we've
> only got a 2mb leased line to our ISP..
>
> Whats important to us:
> - ease of configuration and ongoing management
> - cost effectiveness
> - suitability to Industry (Financial)
> - logging ability/high quality reports/audit trail
>
> The products I'm currently looking at are:
> - Tipping Point 50
> - Cisco IDS 4215
>
> Any ideas, opinions, guidance?
>
> Regards,
> Steve.
>
>



Relevant Pages

  • Re: Any IDS Recommendations?
    ... Please ignore this if your site is not a High Security site. ... If you are using SSL, then where is the End Point? ... For a high security site, logging SSL traffic is pointless, logging source ... > - ease of configuration and ongoing management ...
    (microsoft.public.security)
  • Re: Any IDS Recommendations?
    ... Please ignore this if your site is not a High Security site. ... If you are using SSL, then where is the End Point? ... For a high security site, logging SSL traffic is pointless, logging source ... > - ease of configuration and ongoing management ...
    (microsoft.public.security.virus)
  • Re: SSL broken after Windows 2003 upgrade
    ... > routes them to the appropriate w3wp.exe based on configuration from WAS ... > WFetch can make both a normal SSL request as well as a Client-Certificate ... SSL Diag tells you that SSL should be working assuming the website ...
    (microsoft.public.inetserver.iis)
  • Re: WCF webservice over SSL and without
    ... encryption/signature is handled by SOAP instead of HTTP (IIS) and should be ... I'm assuming there's some point of endpoint configuration I need to do. ... Are you going to use SSL over Http(the most common and convenient ... Microsoft MSDN Online Support Lead ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: MOD_SSL and MOD_AUTH_OPENVMS
    ... Alan Winston - SSRL Admin Cmptg Mgr wrote: ... > On my system I don't make a separate VirtualHost for SSL. ... virtualhosts.conf file that gets included in the httpd configuration. ...
    (comp.os.vms)