Focus on IDS
IDS vs Application Proxy Firewall Oct 21 2008 06:38PM
maash rajani gmail com (4 replies)
Malicous Domains and IDS/IPS signatures Nov 04 2008 06:37AM
Bhatnagar, Mayank (mbhatnagar ipolicynetworks com) (2 replies)
Re: Malicous Domains and IDS/IPS signatures Nov 08 2008 03:00PM
Sanjay R (2sanjayr gmail com)
[Suspected Spam]Re: Malicous Domains and IDS/IPS signatures Nov 08 2008 06:36AM
Rishi Narang (psy echo gmail com)
Re: IDS vs Application Proxy Firewall Oct 24 2008 09:47PM
JiPi DiNi (jipidini gmail com)
Re: IDS vs Application Proxy Firewall Oct 22 2008 06:30AM
Zhihao Tan (zhihao root sg)
Re: IDS vs Application Proxy Firewall Oct 21 2008 06:56PM
Stefano Zanero (s zanero securenetwork it) (1 replies)
Re: IDS vs Application Proxy Firewall Oct 22 2008 03:56PM
\Zow\ Terry Brugger (zow acm org) (1 replies)
Re: IDS vs Application Proxy Firewall Oct 22 2008 05:08PM
Stefano Zanero (s zanero securenetwork it) (1 replies)
"Zow" Terry Brugger wrote:

> Unless it is a transparent application proxy,

Given. Still, it works at the application layer, otherwise it is a
cunningly-renamed stateful firewall which performs deep inspection.

> Unless it is an IPS, in which case

In which case it is not an IDS, and thus not in scope with the original
question :)

> The difference I'd see is that network IDS/IPS devices typically look
> for specific signatures (sequences of bytes, regular expressions,
> certain flags set in the headers, etc) on a session (TCP, UDP, ICMP)
> or network (IP) level packet.

Counterexamples: Arbor, Lancope

> Most can do some degree of session
> reassembily, but only in so far as to catch signatures which are
> divided across multiple packets.

I'm pretty sure that Martin Roesch, if he reads, will have something to
say here :)

--
Cordiali saluti,

Ing. Stefano Zanero, PhD
CTO & Co-Founder

Secure Network S.r.l.
Via Venezia, 23 - 20099 Sesto San Giovanni (MI)
Phone: +39 02.24126788
Fax: +39 02.24126789
email: s.zanero (at) securenetwork (dot) it [email concealed]
web: www.securenetwork.it

------------------------------------------------------------------------

Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
to learn more.
------------------------------------------------------------------------

[ reply ]
Re: IDS vs Application Proxy Firewall Oct 22 2008 06:05PM
\Zow\ Terry Brugger (zow acm org) (2 replies)
Re: IDS vs Application Proxy Firewall Oct 23 2008 12:16AM
Arian J. Evans (arian evans anachronic com)
Re: IDS vs Application Proxy Firewall Oct 22 2008 06:17PM
Stefano Zanero (zanero elet polimi it)


 

Privacy Statement
Copyright 2010, SecurityFocus