Firewall Wizards mailing list archives
Re: IDS outside of firewall?
From: Woody Weaver <woody () wiltelnsi com>
Date: Tue, 04 Aug 1998 22:13:39 -0700
At 05:10 PM 8/4/98 -0600, Henry Hertz Hobbit wrote:
On Mon, 3 Aug 1998, Woody Weaver wrote:<little snip>. I do not believe that for "most organizations" an IDS would detect lots of probes every day. In any event, it can provide an estimate of the threat level of the organization. If I put a passive IDS outside wiltelnsi.com (my return address) I would expect to see almost no probes -- the company is boring, nothing valuable to steal -- and security is designed with that threat level in mind. If I put a passive IDS outside sony.com, where I would expect to see lots of script kiddies with probes, the IDS can justify spending resources to be more careful about security.<big snip>
Summarizing HHH's observations, all of which I agree with: * universities are some of the worst locations for computer security * payroll and student records were "not even touched" [not sure I agree completely with the later] Some reasons people break into sites:
1. They are practicing on your site for bigger game. The script kiddies have to start somewhere!
Indeed, the first place is usually in their own back yard.
2. They are using your site as a hopping point to cover their tracks. This may be harder to do now (doubt it) but it is still a motivator.
No, because of the problem of unsecured universities, and increasingly unsecured unix hosts at high schools and libraries, it is becoming easier.
3. They are a competitor that is probing to see just what they can find out. Yes, I know, you told me that you don't have anything of interest at your site. Don't bet on it.
Perhaps, although because the repercussions of industrial espionage are so high (and easily understood) I would guess that this is less a risk that you offer.
4. Just for the hell(o) of it! [...]
Yes, but... why pick my site? With 47K core routes, I doubt that my site is particularly amusing. On the other hand, this letter will *undoubtedly* stir up some interest. But I think you missed my point. What is needed as a part of any security policy is an accurate assessment of risk. This requires not only evaluating the value of any assets, but the probability of compromise of those assets. (Moreover, the cost of making that evaluation has to be small enough to be included in the cost of the insurance that is the firewall!) Lets suppose I put a passive IDS out there. I find out that someone is smurfing my little 56K line, until they get bored. They toss teardrops against my unix boxes. I find my DNS is poisoned. I find that my anonymous ftp site is filled with 100M of WaReZ, until they realize that that's the size of the hard drive. The IDS hasn't added to my life. They go away when they get bored, I clean out the waste, and reboot. I don't have to spend my time trying to analyze the line, and the company can rent out my time to turn a profit. I've got filters in place to ensure that I'm not used to harm others (and thus be a good netizen) and that seems to work.
Now I will grant you that an external IDS probably isn't going to provide you with much of anything for somebody in your position. But until you put it there, you have a sort of dark question mark about what is going on out there. I have a feeling that you would be surprised at the number and kinds of probes that you say aren't going on.
There are lots of things in my life that are question marks. Partly, its because it doesn't matter. Partly its because I can't spend the resources to resolve the question. Yes, its possible I'd be surprised. However, I believe in the theory that you don't have to run faster than the bear -- just faster than your fellow travelers, and you have to be prepared to be eaten once in a while. This is the (mathematically?) correct solution to this sort of threat assessment. --woody -- Robert Wooddell Weaver email: woody.weaver () wiltelnsi com Network Engineer voice: 510.358.3972 Williams Communication Solutions pager: 510.702.4334
Current thread:
- IDS outside of firewall? Rik Farrow (Aug 02)
- Re: IDS outside of firewall? Jennifer Galvin (Aug 03)
- Re: IDS outside of firewall? Craig H. Rowland (Aug 03)
- Re: IDS outside of firewall? Joseph S. D. Yao (Aug 03)
- Re: IDS outside of firewall? Jeff Sedayao (Aug 05)
- Message not available
- Re: IDS outside of firewall? Marcus J. Ranum (Aug 03)
- Re: IDS outside of firewall? Jennifer Galvin (Aug 03)
- Re: IDS outside of firewall? Woody Weaver (Aug 03)
- Re: IDS outside of firewall? Henry Hertz Hobbit (Aug 04)
- Re: IDS outside of firewall? Woody Weaver (Aug 05)
- Re: IDS outside of firewall? Henry Hertz Hobbit (Aug 04)
- Re: IDS outside of firewall? Stephen P. Berry (Aug 03)
- <Possible follow-ups>
- Re: IDS outside of firewall? Ryan Russell (Aug 03)
- Re: IDS outside of firewall? Jennifer Galvin (Aug 03)
- Re: IDS outside of firewall? Ryan Russell (Aug 03)
- Re: IDS outside of firewall? Marcus J. Ranum (Aug 03)
- Re: IDS outside of firewall? Jeff Maddox (Aug 04)
- Re: IDS outside of firewall? Marcus J. Ranum (Aug 03)
- Re: IDS outside of firewall? Paul Howell (Aug 04)
- Re: IDS outside of firewall? ark (Aug 05)
- Re: IDS outside of firewall? Joseph S. D. Yao (Aug 06)
