Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: IPS false positives |
|---|---|
| Date: | Fri, 14 Apr 2006 09:43:19 -0700 |
Paul, Thanks for the feedback. I would like to better understand what seems like quite a contrast in your statements. At first, you define with seemingly broad strokes whole categories of signatures that an IPS won't/can't block by definition. Then you state that these whole categories that are not blocked make up less than 1% of the spectrum, and further that this number is in overall decline. How can those two positions be reconciled as you have done? You also refer to "very good numbers on this metric." I'm curious about the numbers on the metric you refer to. What are they? What does the metric look like? ============= My questions derive from the following portions of your mail. Below you list five categories of signatures that do not block by default on your IPS.
we prefer to recommend blocking for a signature after it has been in the field for a month or two.
ISS also has anomaly based signatures... these tend not to be candidates for default blocking
policy enforcement signatures... these are not candidates for a default blocking policy.
ISS provides a large number of audit signatures...generally blocking is a bad idea with these as they trigger on normal traffic by design.
In some cases, signatures are disabled by default (and therefore have no blocking) for performance reasons.
============== Drawing from this, you state the following conclusions:
You ask how many false negatives can get through a default IPS
configuration?
It is now easily less than 10% (probably less than 1%). So, our percentage blocked increases with each update.
~~~~~~~~~~~~~~~~~~ Brian Basgen IT Security Architect Pima Community College ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: IDS vs. IPS deployment feedback, Stefano Zanero |
|---|---|
| Next by Date: | Re: IDS vs. IPS deployment feedback, Randal T. Rioux |
| Previous by Thread: | Simulating Retransmissions, Mike Gibson |
| Next by Thread: | Less well-known commercial IDS, James Harless |
| Indexes: | [Date] [Thread] [Top] [All Lists] |