Home > Security Tips > Network Security Tactics > Q&A: Advanced intrusion defense
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Q&A: Advanced intrusion defense


Crystal I. Ferraro, Editor
02.03.2004
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In recent months, intrusion-detection and -prevention systems have made significant strides in helping organizations defend against cyberthreats, exploits and malware. Joel Snyder, senior partner with Opus One, recently joined us for a webcast where he surveyed the landscape of new technologies and best practices for increasing the intelligence of an organization's overall intrusion defense. Here is a small sample of questions that Joel addressed during the webcast, Advanced intrusion defense.

Even with target-based IDS, isn't there a large component missing from most IDS solutions because there isn't a comprehensive log of all network activity? Without a tool that does this, how do you investigate incidents?
I think that log tools are useful, but largely impractical for all but the most trivial networks. We have learned to live without them.

How do you like Network Associates' Intrushield IPS? It seems like a good all-in-one system.
Network Associates does not participate in the reviews I have done on IDS, so I have not had a chance to properly evaluate their product. I am generally wary of products that are afraid to be compared head-to-head with the industry leaders. NAI dropped out of three consecutive reviews, so I don't think it is just coincidence.

In your example of the Blaster TFTP server slipping by ISS, was the event of the actual infection caught and correlated to the fact that the patches were missing? If not, how come?
Yes, it was caught, but ISS was unable to sort that out from a bunch of other attacks that were not an issue. Because of the noise level, ISS effectively "missed" the attack. You might be able to dig it out of the forensics, but that's not useful in this case.

Is there a good guide for developing a security policy?
I always tell people to start with Charles Cresson Wood's books on information security policy development. He has been doing it for over a decade and has a lot of good advice from the trenches. His books are a little expensive, but they pay off very, very quickly. I have not found a good Internet resource on security policy development.

What IDS would you recommend for Windows networks?
The same as any network. Windows is obviously a bigger deal than an all-Unix network, but the rules are the same. My current feeling is that ISS leads the pack in IDS technology. This doesn't mean that they are the best for everyone.

What kind of Linux software is available to build an IDS?
Snort is the best freeware IDS, although it requires a large number of add-ons to make it usable. Be prepared to spend a week or two building up a good one.

What are your thoughts on heuristic scanning?
I think that active scanning has a lot of issues, not all of which are independent of the choice of scanning method. Anything that causes scanning to crash fewer systems and return better data is a good thing. People need to work on this, and fortunately they are.

How does ACID with a Snort console fit into these commercial products?
I have had poor luck in making a usable IDS out of freeware components for any but the smallest of networks or the most specific of tasks. This might be my own shortcoming as a generalist, but I would think twice before going back down that path. The amount of work to make it "right" is often higher than the value.

How capable is Symantec Gateway Appliance with built-in IDS capability?
It's not bad. I have only had limited exposure to it, but it looked pretty nifty to me. Symantec is, slowly, getting its act together for more than desktop security. I'd short-list them if I were selecting a product. The issue I have with them is their proxy-based approach, and that's one that is very difficult to deal with in any environment. Performance is just a killer.

What are your thoughts on the standards work in this area for common event formats, policy?
Anything that increases interoperability of products is a good idea. I have seen very, very poor uptake by the security community of standards. Starting with SNMPv3 and moving on forward, all kinds of management standards have also been poorly received. So I would say that I support the concept, but doubt that we will get much help over the long term. What has succeeded better are vendor-specific APIs like OPSEC. I have stopped discarding these out-of-hand because they seem to be helping in this area. Still, I have no hope that there will be any solid development in security policy standards; the groups are just too clueless. Look at IPsec and see how far they are from reality, even after living with IKEv1 for almost a decade.


To learn about the evolution of "target-based" IDS, the use of OS fingerprinting and vulnerability scanning to increase defense intelligence and more, download the webcast or view Joel's presentation without streaming audio.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




BROWSE BY TAG
Intrusion Detection,   Infrastructure and Network Security,   General Information and Discussion,   Tools and Utilities,   Common Vulnerabilities and Prevention Tips,   Intrusion Detection,   Network Security Tactics,   Network Intrusion Prevention (IPS),   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Network Intrusion Detection (IDS),   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Intrusion Detection
The best of SearchSecurity.com
Crash course: Snort
Audio webcast: Advanced intrusion defense
Presentation: Advanced intrusion defense
Security Alert: Mydoom-A
Intrusion defense
Taking aim
Comparison chart: Target-based NIDS
Target-based IDS muffles the noise to take aim on the alerts that count
Infosec Know IT All Trivia: Intrusion detection

General Information and Discussion
The best of SearchSecurity.com
21st-century firewalls
Best practices for patch management
Audio webcast: Advanced intrusion defense
Presentation: Advanced intrusion defense
Security Alert: Mydoom-A
Intrusion defense
Taking aim
Comparison chart: Target-based NIDS
IDS vs. IPS

Tools and Utilities
Best practices for patch management
Audio webcast: Advanced intrusion defense
Presentation: Advanced intrusion defense
Intrusion defense
Taking aim
Comparison chart: Target-based NIDS
Vulnerability scanning with Nessus
Network security monitoring
Security product and tool reviews
Ain't misbehavin': Security tools watch behavior to stop new threats

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts