Firewall Wizards mailing list archives

Re: IDS outside of firewall?


From: sedayao () orpheus sc intel com (Jeff Sedayao)
Date: Wed, 5 Aug 1998 14:45:24 -0700 (PDT)

[stuff deleted]

Are there advantages to putting an IDS on the outside of the firewall?
Maybe, if it can report and log anything the firewall can't.  But isn't
that just a sign that the firewall is not configured properly?  And if
firewalls drop all suspicious traffic anyway, would this just serve as a
report-generator?  I'm curious, though, what these are, if anyone has any
ideas.....

The general guideline I like to go by is if you don't know what to do
with data, then don't collect it.  People have mentioned some things to
do with your data - do studies of attack techniques (most people don't
have the time for this) or use the data to justify your firewall or
security budget (definitely a useful thing).  The only thing else that
I can think of is to track whether attempted attacks or probes are
chewing up a substantial portion of your Internet connection bandwidth.  
For example, if you see that someone is eating up 25% or more of your 
Internet T1 or T3 with some denial of service attack, then you should 
seriously look at tracking down and stopping those attacks.  Stopping
such an attacker could give you considerable return on your investment
of time.

Other than the above reasons, I can't see any other benefit.
-- 
Jeff Sedayao
Intel Corporation
sedayao () orpheus sc intel com



Current thread: