Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

Re: [Full-disclosure] Suggestion for IDS

Subject: Re: [Full-disclosure] Suggestion for IDS
Date: Wed, 28 Sep 2005 09:24:19 -0400
Our company plan to install IDS to protect our resources, I'm already read about snort as NIDS, but, that's software based. I'm interesting with hardware based that will work transparently with our Cisco PIX, no need to make changes in our firewall. What's your suggestion.

My first piece of advice on this is to ignore any company that says they deliver a "turnkey" solution. Such a thing doesn't exist.


Any IDS will work with any firewall .. unless, of course, you want to connect the two together (eg: dynamically ACL the PIX based on what the IDS sees). That, IMHO, is an invitation do DOS yourself (think .. I spoof a packet that --looks like an attack-- from your upstream router, or smtp server, etc). There's dozens of ways to do this, including free with snort.

You can also examine snort's "inline" mode in which you setup bridging between two interfaces, and let snort "decide" which packets to forward. In order to make such a thing redundant, be prepared to do some fancy H/A stuff with a pair of servers.

And don't forget .. an IDS is certianly not "fix and forget" .. it requires daily tinkering (new sigs come out daily .. and they're almost always noisy and require tuning). In most any decent sized network, having a dedicated admin to chase the IDS alerts and keep an eye on things is almost a given.

And as for having an IDS "protect" your network .. well .. forget that. An IDS is great for statistical research and forensics .. but with botnets and whatnot going SSL, you're time/resources are much better spent finding your vulnerabilities and patching your hosts.

My $0.02.


Cheers,

Michael Holstein CISSP GCIA
Cleveland State University
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>