ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Surveillance or dead lock?

Laura Taylor

Published: 20 Aug 2002 20:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Intrusion prevention is an outgrowth of intrusion detection, and intrusion prevention products offer different functionality from intrusion detection products. IT decision makers need to understand the differences so that they can determine which type of product will provide the best safeguards for their systems.

Understand the IDS challenge
Intrusion detection systems (IDSs) are surveillance products. Using an IDS is somewhat like putting an x-ray machine on your network so that you can examine your packets to see what's inside. IDSs are really more similar to protocol analysers or smart sniffers than they are to intrusion prevention systems (IPSs). IDSs look at the patterns of the traffic going through your networks and try to make intelligent decisions regarding their findings.

IDSs can be set up to log information continuously or to log information and then effect a response from the information they collect. In most cases, IDSs are installed on network segments in strategic locations (say, between your border router and your internal mission-critical application servers).

There are a few fundamental problems with how some IDSs work today. First, as more and more network traffic becomes encrypted, IDSs become useless because they can't parse encrypted traffic. Second, as networks become more heavily switched, they typically see only a small amount of the traffic on your network. On a switched network, you need to greatly increase the number of intrusion detection sensors to monitor traffic on all the network segments. On large networks, this means that the total cost of ownership of IDSs can be very high. Third, IDSs generate a huge number of false positives, telling you that your network is being attacked when it's not. These three problems are leading many companies to switch to IPSs.

Leading vendors in the intrusion detection market include Cisco, ISS, and NFR. Some IDSs are sold as software packages you install on top of a leading operating system. Others are sold as turnkey appliances, commonly called "sensors" by the companies that make them. Typically, these devices work by monitoring the traffic on the network, noting which devices they are communicating with and categorising the types of traffic interacting with the devices. Traffic patterns are compared against known attack signatures, and alarms are typically set to go off according to certain thresholds and severity levels. For example, a syn-flood attack might be set to a severity level of high, and an ICMP flood might be set to medium.

IDSs typically use known signatures to recognise traffic patterns, similar to the way antivirus products use known signatures to recognise viruses. As with an antivirus system, it's important to keep the signatures up to date. The signatures are often based on malicious TCP/IP packets, since cybercriminals commonly try to manipulate those packets to perform a malicious action. Therefore, the types of information that IDSs usually record are source address, destination address, port numbers, encryption keys, MAC addresses, and whether packets are formatted correctly.

Some IDSs monitor what services are being used, which can be compared against what services are currently not allowed by the organisation's security policy. However, if your firewall rules are properly configured, no services should be passing through to your internal network unless they are expressly allowed (although it would be naive to assume that all firewalls have properly configured rule-sets). It is truly important to tune an IDS to report only the minimum data needed to detect an attack. Storing information on every packet header and payload is not useful, and in the long run, it will just create more work and overhead by taking up valuable disk space, requiring additional backups, and increasing storage requirements.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
98 out of 209 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

Senior Software Engineer (JAVA/J2EE)

Ability to work with large, multiple data sets -Proficient in Object Oriented design and development -Ability to formally communicate architectural ...

System Administrators/ Unix/ Linux/ TCP/IP/ Scripting/ 24/7/ London

Additionally you must have experience of TCP networking, Firewalls, scripting tools and ideally some Mysql or Oracle. System Administrators/ Unix/ ...

Central Systems Manager

Detailed knowledge of TUI's infrastructure * Experience delivering complex IT projects * An understanding of commercial needs, with a strong ability ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

Post a comment