Home > Security Tips > Network Security Tactics > How to determine network interface cards for IDS sensors
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

How to determine network interface cards for IDS sensors


JP Vossen, CISSP
05.05.2005
Rating: -4.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


After deciding on an operating system (OS) to use for your Snort IDS sensors, you will need to configure networking. Ideally, you should have a minimum of two network interface cards (NICs). One of these is used for sniffing and should be un-numbered -- that is, not have an IP address assigned to it. The other should have an IP address as usual and be used only for management. Also, you may have as many additional network interfaces as you like -- numbered or un-numbered -- provided the hardware and operating system can support them.

The management interface should be on a trusted network, usually your LAN, or a dedicated management VLAN or segment. You can configure it as you normally would for your OS and environment.

For un-numbered interfaces, having no IP address on the un-trusted or monitored segments adds a layer of security. Since there is no IP address to target, those segments are much harder to attack, but not foolproof. By definition, Snort sees the traffic. Therefore a vulnerability in Snort or the network packet capture library may still be exploited, and this has happened in the past. Remember, your sensor is a security device and should be configured, hardened and maintained with that in mind.

Windows, Unix and Linux all support un-numbered interfaces. For example, to bring up eth1 as an un-numbered interface on a Red Hat or derivative Linux distribution, use your favorite text editor to create or edit /etc/sysconfig/network-scripts/ifcfg-eth1



so it looks like this:

DEVICE=eth1
ONBOOT=yes

Running an un-numbered interface under Windows is also easy, but counter intuitive. For example, under Windows 2000 simply right click on "My Network Places" and choose Properties. Right click the appropriate connection, e.g. "Local Area Connection 2" and choose Properties again. Verify that you are working with the correct physical interface by checking the name and/or properties (i.e. MAC address) of the network interface card, then uncheck all components, especially "Client for Microsoft Networks" and "Internet Protocol {TCP/IP}." You would think this action disables the card, but it doesn't. It will not show up under ipconfig /all, but it will if you use the snort –W command. Run snort –W and note the number of the interface you will use for sniffing (e.g. 2), then test that Snort is working by a command like snort –vi 2. If Snort suddenly stops working in the future, check snort –W again as Windows sometimes changes the interface numbers when you make changes to networking.

In any case, make sure you cable appropriately after configuring your un-numbered network interface. You don't want to plug the management interface into the un-trusted segment or vice versa.

[TABLE]

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Network Intrusion Detection (IDS),   Network Intrusion Detection and Analysis,   Enterprise Network Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security Tactics
Screencast: Samurai offers pen-testing nirvana
Firewall rule management best practices
Chained Exploits: How to prevent phishing attacks from corporate spies
Rootkit Hunter demo: Detect and remove Linux rootkits
Enterprise UTM security: The best threat management solution?
Making the case for network security configuration management
An inside look at security log management forensics investigations
How to find sensitive information on the endpoint
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
How to spot attacks through Apache Web server log analysis

Network Intrusion Detection (IDS)
SIMs tools and tactics for business intelligence
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
New product aims to control rogue applications that avoid firewalls
What is the cause of an 'intrusion attempt' message?
Host-based intrusion prevention addresses server, desktop security
Intrusion detection vs. intrusion prevention
Product review: AirDefense Enterprise 7.3
Best practices for IDS creation and signature database maintenance
Network intrusion prevention systems: Should enterprises deploy now?
Network Intrusion Detection (IDS) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
computer forensics  (SearchSecurity.com)
Diffie-Hellman key exchange  (SearchSecurity.com)
Einstein  (SearchSecurity.com)
HIDS/NIDS  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)
ultrasound  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts