Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

RE: IPS technology question.

Subject: RE: IPS technology question.
Date: Tue, 30 Aug 2005 05:22:57 -0400
Hi David,

A standard PCI bus (PCI-X, 133Mhz) is only capable of 1.06Gbps.  This means
530Mbs in, and 530Mbs out, not taking into account things like hard-disks,
logging/reporting and any packet inspection, which only serve to pull this
number down further.
It is architecturally impossible for a standard Intel platform to attain a
throughput of anything higher than 530Mbs, let alone the 2Gpbs you claim
below?
A further explanation of these figures may help clear things up?

Regards,

Tim


-----Original Message-----
From: Swift, David [mailto:dswift@ipolicynetworks.com] 
Sent: 24 August 2005 15:36
To: planz; snort user
Cc: focus-ids@securityfocus.com
Subject: RE: IPS technology question.

There are varying techniques in achieving performance, and FPGAs/ASICs
are not the only way.

The company I work for, iPolicy Networks, put the development effort on
the front end to optimize rules, signatures, and processing rather than
building a better ASIC. We've been able to achieve 140Mbps - 2Gbps on a
single standard Intel platform without FPGAs by pre-compiling the rules
into a state engine, and pushing them down to an Intel platform.

On the high end to reach 4Gbps we used clustered Intel Network
Processors. Again, no custom ASICs required, just intelligent parallel
processing, and pre-compilation with bounded rules.

As to the total number of vendors, Gartner said last year there were
over 700 vendors in the security space. And it seems everyone messages
the same thing whether or not they can do it.

-----Original Message-----
From: planz [mailto:planz2009@gmail.com] 
Sent: Tuesday, August 23, 2005 9:14 PM
To: snort user
Cc: focus-ids@securityfocus.com
Subject: Re: IPS technology question.

I don't get, what do you mean by "Percentage", since we have uncounted 
number of vendors/brands of IPS today.

If you look at the technology angle, the vendors who are offering both 
Software and Appliance versions of the same IPS, falls into the first 
category. To take a look back at the market, we find only very few 
vendors, like ISS, Snort, Dragon, ...hmmm..  Can somebody help to 
fill-up the list.

Whether it is IDS or IPS, it is important to look at the Detection 
Technology. If it cannot detect, how can it alert or prevent?

In an IPS world, firewall plays behind the scenes;  since the IDS is 
configuring the built-in firewall feature to block.


snort user wrote:

Greetings.

What percentage of the IPS systems are out there, which does not use
co-processors/FPGA etc..

What percentage of the IPS systems depend on firewalls like iptables
and ip filter ?

I am just trying to get an idea of what is the state of art in the IPS
technology space.

Any information is appreciated.

Thanks

-----------------------------------------------------------------------
-
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to
http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
-----------------------------------------------------------------------
-


 



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708

to learn more.
------------------------------------------------------------------------


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>