Home > Security Tips > Network Security Tactics > Run, don't walk, toward IPS security
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Run, don't walk, toward IPS security


Jonathan Hassell
05.23.2005
Rating: -5.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



What you will learn from this tip:
Learn why organizations should deploy an intrusion-prevention system (IPS) ASAP.

Intrusion-detection systems (IDS) and intrusion-prevention systems (IPS) are a significant growth area in the security market today -- and there's no sign of a slowdown.

Annual worldwide IDS/IPS product revenue is projected to grow rapidly through 2007, when it will reach $972 million, according to Campbell, Calif.-based Infonetics Research. Yet one of these tools is far more crucial to the success of your Windows security efforts than the other -- and you must adopt it now if you haven't already. I'm talking about IPS.

If you're not familiar with IDS and IPS, they are systems that track attempts to access a network.

IDS: The nerves

An IDS tool works in tandem with other systems you probably have deployed at the edge, including firewalls and routers, and reports to administrators when it encounters suspicious activity that may indicate or result in an intrusion. Think of this type of system like your body's nerve center, which alerts you to problems via pain.

IDS technology is based on a two-decades-old concept of monitoring Windows systems and networks. Most robust, enterprise-class firewall and routing products today include at least some functionality that reports to a monitoring system when bad things begin to happen on the wild side of the edge.

IPS: The white blood cells

An IPS tool goes one step further, identifying potential malfeasance in context so that it can, by itself, direct other systems to shut off an attack. These systems are more closely associated with white blood cells, which actually fend off intruding bacteria, viruses and the like.

IPS technology is relatively new to the scene, primarily because the sophisticated logic and communications required for these tools to make just-in-time decisions and pass commands on to sister devices has only recently become available in the mainstream.

Are we actually seeing more IPS adoption with this wider, richer offering? I don't think we are -- but we should be. Allow me to evangelize.

We have to do more. An IDS offers useful alerts, but they're like messages to the President in a Tom Clancy novel: 'A nuclear warhead is on its way to Washington. What are you going to do about it?' You have to scramble a team, most likely to scour the reports and ascertain more data than the IDS report will give you, identify the affected systems and shut out the attacker. All of this has to take place within an impossibly short amount of time before the attacker is able to cover his tracks enough that you won't be able to know what he's touched. (If you aren't sure if a cracker has been on a machine, assume he has: Guilty until proven without a doubt innocent.)

An IPS can save a lot of that effort, but the real advantage is the speed in which it can perform these actions. I can't imagine a day when security breaches will be handled without any manual intervention whatsoever, but I can predict the day when the breach itself can be stopped within a few seconds of its occurrence, relieving the response team of the urgency to wall off the affected system.

An IPS isn't perfect, but what is? It has to be customized for your specific network design; it has to be aware of what it is commanding; it has to understand the type of traffic you normally sustain; and it needs to be updated on the spot regularly without any sort of problem. An IPS is expensive, mainly because the processor power required to analyze and detect patterns within the traffic constantly driven at the box is not cheap, and it will give you your share of false positives.

An IPS may not be a panacea, but breaches are seen every day and our current solutions aren't cutting it anymore. We need to look to IPS to provide the next step in that quest to harden.


More Information

About the author: Jonathan Hassell is an author, consultant and speaker residing in Charlotte, North Carolina. Jonathan's books include RADIUS and Learning Windows Server 2003 for O'Reilly Media and Hardening Windows for Apress. His work is seen regularly in popular periodicals such as Windows IT Pro Magazine, SecurityFocus, PC Pro and Microsoft TechNet Magazine. He speaks around the world on topics including networking, security and Windows administration.

This tip originally appeared on sister site SearchWindowsSecurity.com.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Intrusion Detection (IDS)
What are best practices for creating an IDS and maintaining a signature database?
Network intrusion prevention systems: Should enterprises deploy now?
RSA 2008: Sourcefire founder Roesch previews Snort 3
Screencast: Opening up the Network Security Toolkit
Can a firewall alone effectively block port-scanning activity?
Should an intrusion detection system (IDS) be written using Java?
What security risks do enterprise honeypots pose?
What are the benefits of 'in-the-cloud' network security services?
Screencast: Snort -- Tactics for basic network analysis
Can Snort stop application-layer attacks?
Network Intrusion Detection (IDS) Research

Network Intrusion Prevention (IPS)
Network intrusion prevention systems: Should enterprises deploy now?
What security risks do enterprise honeypots pose?
What are the benefits of 'in-the-cloud' network security services?
What is a 'top-down' IPS sensor search?
Is a 'self-defending network' possible?
Best practices for purchasing an intrusion detection device
VeriSign, AirMagnet team up for wireless IPS
Sourcefire, Nmap deal to open vulnerability scanning
Interop: Vendors update software, demonstrate new security features
McAfee launches IPS for 10g networks, but is IT ready?
Network Intrusion Prevention (IPS) Research

Tips
Security rituals
Don't be the first on the block to own SP2
The 9/11 Nimda chaser

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
computer forensics  (SearchSecurity.com)
Diffie-Hellman key exchange  (SearchSecurity.com)
Einstein  (SearchSecurity.com)
HIDS/NIDS  (SearchSecurity.com)
intrusion detection  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)
ultrasound  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts