Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 61 guests and 3 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Incident Response
How valuable is IDS?
EH-Net
May 22, 2013, 04:22:57 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Incident Response
(Moderator:
don
) >
How valuable is IDS?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: How valuable is IDS? (Read 6669 times)
0 Members and 1 Guest are viewing this topic.
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
How valuable is IDS?
«
on:
July 18, 2012, 09:31:11 AM »
I've seen several recent comments elsewhere questioning the value of IDS. I'd like to what other people think about it.
I've managed an IDS in the past and conducted some IDS research for a former employer, but it's been several years since I did any hands-on IDS monitoring so I feel like I'm lacking a current perspective.
The argument that I've always accepted is Bejtlich's "prevention eventualy fails." I still think that argument is valid and can see the value of monitoring systems, logging, keeping session/statistical data both for detection and response, etc. But, I wonder what value IDS actually gives us.
Consider Snort, let's say we remove all of the signatures that aren't applicable to our environment (e.g. remove Oracle rules if we don't run Oracle), remove all of the rules that are too out of date to matter (e.g. teardrop), and also remove all of the rules for things that we're blocking anyway. Once we do that, how much is really left and what are the odds that, if we do undergo a serious attack, that the remaining rules will alert us to it?
Although prevention eventually fails, the detection systems that we put into place is only valuable if they are able to detect malicious activity when prevention fails. Otherwise, we don't gain any additional security.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
nicklauscombs
Newbie
Offline
Posts: 28
Re: How valuable is IDS?
«
Reply #1 on:
July 18, 2012, 02:21:16 PM »
It is only that: a tool. By itself without staff who can interpret, other security controls, etc.... it probably would be a paperweight.
I believe a properly configured and maintained IDS used along with other aids adds value to a security program. Ultimately any additional alerts, data, insight, etc... I can get I will be more than happy to take.
Logged
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: How valuable is IDS?
«
Reply #2 on:
July 18, 2012, 02:45:44 PM »
My immediate concern isn't managing, tuning, or responding to attacks. Assuming an organization can handle that, what value does the IDS actually bring? What is its capability to actually detect attacks?
I've seen numbers for AV (they aren't reassuring), but not IDS. I'd love to have some hard data or even casual observations from the field as to what various IDS are actually capable of.
Put another way, I'd like to know how many false negatives there are. I want to know how much passes "under the radar". If IDS can only detect 10, 20 or 30% of attacks, then it's not a very valuable tool. If it can detect 70% or more, the benefits become a lot more significant.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
hayabusa
Hero Member
Offline
Posts: 1632
Re: How valuable is IDS?
«
Reply #3 on:
July 18, 2012, 10:58:18 PM »
While I don't have facts and figures for you, I'll say this...
An IDS (or IPS, or any other security measure) is only as good as the person / people who configure them. I've seen folks see significant value from theirs, when the right folks set them up, and then CONTINUE to proactively monitor and tune / adjust. Then there are others who complain, but when I look at their configurations, it's obvious why (and under the same configs, I'd be displeased, too.)
Do I rely solely on them? Heck no. But do I feel they CAN be of value / benefit? Absolutely.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: How valuable is IDS?
«
Reply #4 on:
July 18, 2012, 11:26:02 PM »
I've brought this up elsewhere and a common response is that the value depends on the person running it, but the person running it is responsible for tuning the IDS for performance and sifting through false positives. Let's assume tuning is not an issue. I can enable all the rules I want without running into performance problems and, by magic, the false positive will still be low. Will the IDS catch the stuff I really care about? Looking at Snort, it seems to me that a lot of the rules catch older attacks or very generic patterns that are easy to avoid (e.g. 0x90 NOP sleds).
Have you used them to successfully detect any attacks that weren't super-obvious (e.g. a Nessus scan)? Have you had any slip by (that you know of)?
Logged
BS in IT, CISSP, MS in IS Management (in progress)
nicklauscombs
Newbie
Offline
Posts: 28
Re: How valuable is IDS?
«
Reply #5 on:
July 19, 2012, 07:07:12 AM »
there's too much grey area in what you're asking. The person tuning the IDS/IPS is the one that will catch potentially malicious traffic using a variety of resources including the IDS. You can't rely on any one tool to do the work. Can you tune the device and write custom signatures to help aid in the work and narrow it down to what you want? of course but ultimately the staff is the focus not a specific device.
Logged
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: How valuable is IDS?
«
Reply #6 on:
July 19, 2012, 02:21:32 PM »
I'm focused on the existing rule sets, either those available from the IDS vendor or a third-party project such as Emerging Threats. What you can actually detect with the default rule set? Most of what I see in the rule sets is old, easy to avoid, or too noisy (e.g. port scans if you looking at Internet-originating traffic).
My concern is that we don't spend much time evaluating how effective IDS actually is. This has been the case with anti-virus as well although it's easier to find data for that since AV is more widely deployed.
The ultimate answer may be that IDS is extremely effective, but I don't want to assume that. I want to challenge our assumptions to get to something more objective.
I understand the concept of tuning the IDS, turning off rules that generate too many false positives, creating some custom rules to fit local policy, etc. That's all well and good. But, underneath that we're depending on someone else to deliver a base set of rules and capabilities that are supposed to detect malicious traffic and I'm not convinced about the effectiveness of what is being delivered.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
nicklauscombs
Newbie
Offline
Posts: 28
Re: How valuable is IDS?
«
Reply #7 on:
July 20, 2012, 06:38:14 AM »
Quote from: unicityd on July 19, 2012, 02:21:32 PM
I'm focused on the existing rule sets, either those available from the IDS vendor or a third-party project such as Emerging Threats.
When just talking about standard default rules I think is where having mutiple IDS devices working together becomes valuable. High level example being maybe you run Cisco IDS/IPS along with something like SecurityOnion on the same network segment to get potentially differing views/alerts of traffic going through to compare against each other.
Logged
3xban
Hero Member
Offline
Posts: 608
Re: How valuable is IDS?
«
Reply #8 on:
July 21, 2012, 06:44:15 AM »
Well in most cases your IDS and IPS are one in the same. Only major differences is you tell your IPS side to block specific signatures. Other than that you tell them both to ignore traffic related to platforms you are not using. You want them both to log and in some cases you allow certain devices to pass through unhindered. For instance anything going to your honeypot, you might want to allow through without blocking but you definitely want to log it for analysis.
Also it is about placement. My last job we had an IDS/IPS that first was sitting in the rack for like 2 years and all it was doing was passing traffic between the internet and LAN. I had to call support to get the thing updated since no one bothered doing that for the 2 years. So once I got that all squared away I turned turned on the logging to get a baseline and disabled the logging for the platforms I know I didn't have. After that it was a couple weeks of tweaking until I knew I could turn on the IPS part without breaking the network. I was getting some decent traffic, most of which was valid. Then some genius decided to have it moved from the main internet line where most of our high traffic devices where to a secondary line where the only thing that existed was email which was going through a filtered service. Guess what happened.... nothing.
And I was happy to report the plan that the ISO and network engineer implemented failed miserably. Oh and yes, we (my boss and I) did recommend alternatives but there was a trust issue with the support staff due to previous members who were no longer there. I was not sad when they announced they were outsourcing all our jobs, I laughed and gave my notice. Told them where I was going and almost felt like telling them yeah, that's right bitches, going to move into some real shit
Sorry for the side story
Logged
Certs: GCWN
(@)Dewser
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: How valuable is IDS?
«
Reply #9 on:
July 21, 2012, 03:29:28 PM »
A big part of this is going to be how well you baseline and how well you know your environment. The initial attack may be able to circumvent the IDS, but if a database server establishes an outbound HTTPS connection when it has
never
done that before, you can be sure something abnormal is underway. It may be an attacker, it may be your DBA checking his email because that server isn't subject to web filtering. Regardless, it signifies activity that's probably worth looking into.
This is why you need to correlate IDS with netflow, local system logs, etc., so you can connect the dots and get better visibility into network and systems operations. Just standing up Snort, Proventia, etc. on the perimeter is wholly inadequate.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Eleven
Full Member
Offline
Posts: 120
Re: How valuable is IDS?
«
Reply #10 on:
July 24, 2012, 08:02:59 PM »
Quote from: unicityd on July 18, 2012, 02:45:44 PM
My immediate concern isn't managing, tuning, or responding to attacks. Assuming an organization can handle that, what value does the IDS actually bring? What is its capability to actually detect attacks?
I've seen numbers for AV (they aren't reassuring), but not IDS. I'd love to have some hard data or even casual observations from the field as to what various IDS are actually capable of.
Put another way, I'd like to know how many false negatives there are. I want to know how much passes "under the radar".
If IDS can only detect 10, 20 or 30% of attacks, then it's not a very valuable tool. If it can detect 70% or more, the benefits become a lot more significant.
I don't think you're being very fair to IDS. People criticize IDS because they can be bypassed, but really what preventative measure can't be bypassed? Intrusion detection is a lot more than an IDS, just like preventing attacks is a lot more than a firewall. Neither is meant to be the only thing needed for detection/prevention.
Logged
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: How valuable is IDS?
«
Reply #11 on:
July 25, 2012, 09:16:33 AM »
My concern isn't that there is some way to bypass an IDS. As you point out, everything can be bypassed, at least in certain circumstances. My concern is that the effectiveness of IDS at detecting malicious traffic is so low that it is not cost effective. Even if IDS only detected 5% of malicious traffic, it would be useful if it were cheap and required little maintenance. But, it costs money to deploy IDS and, as many others pointed out, you need one or more good analysts to run them. For the level of investment that it actually takes to run and maintain and IDS, the benefits need to be greater.
I don't think that IDS is worthless. I just suspect that it's not the best use of scarce resources.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
Eleven
Full Member
Offline
Posts: 120
Re: How valuable is IDS?
«
Reply #12 on:
July 25, 2012, 10:04:41 AM »
1. You don't have to monitor the entire organization. You can monitor your most important or most vulnerable systems.
2. There are around 8000 vulnerabilities found a year, but only around 13 that are commonly exploited [
source
]. So I think you can get by with a far more conservative ruleset than the default.
3. You don't have to investigate and respond to every alert in real time. You could only resond to critical alerts and leave others for forensic purposes.
I wouldn't say an IDS is appropriate for
everyone
, but an IDS is what you make it. You can make a firewall a nightmare to manage by using a really conservative ruleset where you have to continually make exceptions. You could also make an IDS a nightmare to manage by using a liberal ruleset where you get overwhelmed by false positives. Not many people do the former, but the latter is a common mistake.
Logged
nicklauscombs
Newbie
Offline
Posts: 28
Re: How valuable is IDS?
«
Reply #13 on:
July 25, 2012, 10:35:31 AM »
Quote from: unicityd on July 25, 2012, 09:16:33 AM
I don't think that IDS is worthless. I just suspect that it's not the best use of scarce resources.
you can always go the no/low cost securityonion route for your IDS monitoring.
Logged
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: How valuable is IDS?
«
Reply #14 on:
July 25, 2012, 11:59:18 AM »
Cheap IDS software is not the issue. It still takes time/money to setup sensors and management consoles (hardware/VMs are cheap at least) and a lot more to staff them. Even with a low false positive rate, IDS need love and affection.
IDS may in fact be very valuable. I'd really like to see some objective evidence that it is valuable rather than make the assumption that it is valuable based on a general notion of defense in depth, prevention fails, etc. We ought to have some idea of what capabilities IDS actually provides, how well it detects malicious traffic, etc. What percentage of actual attacks in the wild can IDS detect? What if we exclude the attacks that are easily prevented? How do the capabilities of the IDS vary by attack type (e.g. web app vs client-side web vs botnet CnC)?
There has been some research on the effectiveness of anti-virus and it's not encouraging (act surprised). My impression is that IDS is further behind the curve than AV.
http://blogs.cisco.com/security/the_effectiveness_of_antivirus_on_new_malware_samples/
http://www.cyveillance.com/web/docs/WP_MalwareDetectionRates.pdf
Logged
BS in IT, CISSP, MS in IS Management (in progress)
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Greetings
: but the desperate effort that comes from being hopeful Nike Blazers Uk
(0) by
Loyatoitada
ChicagoCon 2007
: waterfall Cheap Air Max Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: The advent of the web happened slowly Nike Blazer Uk
(0) by
Loyatoitada
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.