Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: Firewalls (was Re: IDS evaluations procedures)

Subject: Re: Firewalls (was Re: IDS evaluations procedures)
Date: Thu, 21 Jul 2005 05:22:27 +0530
On 18/07/05 21:09 -0400, Richard Bejtlich wrote:
On 7/17/05, Devdas Bhagat <devdas@dvb.homelinux.org> wrote:

An IDS is not an attack prevention mechanism. An IDS is a tool to detect
when your active attack detection mechanisms have been bypassed. An IDS is
passive. It tells you what it can see, but it is not supposed to do
anything to that traffic. Active elements are called firewalls, and
firewalls include both packet filters and proxies.


Wow, I had almost given up hope that anyone else thought this way. 
Bravo Devdas.  The "IPS is better than IDS" crowd ignores the fact
that an IPS is another kind of firewall, not an "improved" IDS.

In fact, you could argue the IPS is a step backward from a stateful
layer 3/4 firewall in that the IPS inverts a proven security model. 

Personally, it is a step backwards from proxy firewalls with an inverted
security model.

Good security (implemented on most firewalls) says "allow what policy
says is authorized, deny all else."  The IPS model says "deny what
policy says is malicious, allow all else."  Marty pointed this out a
while ago and it has stayed with me.

I think IPS is helpful when one needs to make granular access control
decisions based on layer 7 traffic characteristics.  However, large

Proxy firewalls! If it is worth doing, it is worth doing it right.

Devdas Bhagat

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>