Firewall Wizards mailing list archives

Re: IDS outside of firewall?


From: Woody Weaver <woody () wiltelnsi com>
Date: Tue, 04 Aug 1998 22:13:39 -0700

At 05:10 PM 8/4/98 -0600, Henry Hertz Hobbit wrote:
On Mon, 3 Aug 1998, Woody Weaver wrote:

<little snip>.  I do not believe that for "most
organizations" an IDS would detect lots of probes every day.  In any event,
it can provide an estimate of the threat level of the organization.  If I
put a passive IDS outside wiltelnsi.com (my return address) I would expect
to see almost no probes -- the company is boring, nothing valuable to steal
-- and security is designed with that threat level in mind.  If I put a
passive IDS outside sony.com, where I would expect to see lots of script
kiddies with probes, the IDS can justify spending resources to be more
careful about security.

 <big snip>

Summarizing HHH's observations, all of which I agree with:

* universities are some of the worst locations for computer security
* payroll and student records were "not even touched" [not sure I agree
completely with the later]

Some reasons people break into sites:
1. They are practicing on your site for bigger game. The script
  kiddies have to start somewhere!

Indeed, the first place is usually in their own back yard.

2. They are using your site as a hopping point to cover their tracks.
  This may be harder to do now (doubt it) but it is still a motivator.

No, because of the problem of unsecured universities, and increasingly
unsecured unix hosts at high schools and libraries, it is becoming easier.

3. They are a competitor that is probing to see just what they can
  find out. Yes, I know, you told me that you don't have anything
  of interest at your site. Don't bet on it.

Perhaps, although because the repercussions of industrial espionage are so
high (and easily understood) I would guess that this is less a risk that
you offer.

4. Just for the hell(o) of it! [...]

Yes, but... why pick my site?  With 47K core routes, I doubt that my site
is particularly amusing.

On the other hand, this letter will *undoubtedly* stir up some interest.

But I think you missed my point.  What is needed as a part of any security
policy is an accurate assessment of risk.  This requires not only
evaluating the value of any assets, but the probability of compromise of
those assets.  (Moreover, the cost of making that evaluation has to be
small enough to be included in the cost of the insurance that is the
firewall!)

Lets suppose I put a passive IDS out there.  I find out that someone is
smurfing my little 56K line, until they get bored.  They toss teardrops
against my unix boxes.  I find my DNS is poisoned.  I find that my
anonymous ftp site is filled with 100M of WaReZ, until they realize that
that's the size of the hard drive.  The IDS hasn't added to my life.  They
go away when they get bored, I clean out the waste, and reboot.  I don't
have to spend my time trying to analyze the line, and the company can rent
out my time to turn a profit.  I've got filters in place to ensure that I'm
not used to harm others (and thus be a good netizen) and that seems to work.

Now I will grant you that an external IDS probably isn't going to
provide you with much of anything for somebody in your position.
But until you put it there, you have a sort of dark question mark
about what is going on out there. I have a feeling that you would
be surprised at the number and kinds of probes that you say aren't
going on.

There are lots of things in my life that are question marks.  Partly, its
because it doesn't matter.  Partly its because I can't spend the resources
to resolve the question.  Yes, its possible I'd be surprised.  However, I
believe in the theory that you don't have to run faster than the bear --
just faster than your fellow travelers, and you have to be prepared to be
eaten once in a while.  This is the (mathematically?) correct solution to
this sort of threat assessment.

--woody

--
Robert Wooddell Weaver           email:  woody.weaver () wiltelnsi com
Network Engineer                 voice:  510.358.3972
Williams Communication Solutions pager:  510.702.4334



Current thread: