Ips 2
Ips 2
Ips 2
Prevention
IPS v5.02-1
Intrusion Detection
Versus Intrusion
Prevention
IPS v5.02-2
IDS vs IPS
An intrusion detection system has the
capability to detect misuse and abuse of, and
unauthorized access to, networked
resources.
An intrusion prevention system has the
capability to detect and prevent misuse and
abuse of, and unauthorized access to,
networked resources.
IPS v5.02-3
IPS v5.02-4
Intrusion Detection
Technologies
IPS v5.02-5
IPS v5.02-6
IPS v5.02-7
Protocol Analysis
Intrusion detection analysis is performed on
the protocol specified in the data stream.
Examines the protocol to determine the validity of
the packet
Checks the content of the payload (pattern
matching)
IPS v5.02-8
Intrusion Detection
Evasive Technique
IPS v5.02-9
Evasive Techniques
Attempts to elude intrusion prevention and
detection use evasive techniques such as the
following:
Flooding
Fragmentation
Encryption
IPS v5.02-10
Flooding
IPS v5.02-11
Fragmentation
IPS v5.02-12
Encryption
SSL Session
IPS v5.02-13
IPS v5.02-14
Performance (Mbps)
600
250
IDSM-2
IDS 4255
200
IPS 4240
80
AIP-SSM
45
NM-CIDS
10/100/1000 TX
IPS 4215
10/100 TX
10/100/1000 TX
10/100/1000 TX
1000 SX
10/100/1000 TX
Switched/1000
Network Media
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.02-15
Sensor Appliances
IPS v5.02-16
Monitoring Interface
Router
Switch
Sensor
Router
Protected
Network
Command and
Control Interface
Management System
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.02-17
Power LED
Command and
Control Network
Interface Card
LED
IPS v5.02-18
Optional
Monitoring
Interfaces
Console
Port
Monitoring
Interface
Command
and Control
Interface
IPS v5.02-19
Power
Indicator
Status
Indicator
Flash
Indicator
IPS v5.02-20
Command and
Control
Interface
Expansion Slot
Monitoring
Interfaces
Power
Connector
Indicators
Auxiliary
Port
USB
Ports
Power
Indicator
Compact
Flash
Status
Indicator
Console
Port
Flash
Indicator
Indicator
Light
Power
Switch
IPS v5.02-21
Power
Indicator
Status
Indicator
Flash
Indicator
IPS v5.02-22
Command
and Control
Interface
Monitoring
Interfaces
USB
Ports
Status
Indicator
2005 Cisco Systems, Inc. All rights reserved.
Console
Port
Indicators
Power
Indicator
Expansion Slot
Compact
Flash
Power
Connector
Auxiliary
Port
Flash
Indicator
Indicator
Light
Power
Switch
IPS v5.02-23
Promiscuous-Mode IDS
and Inline-Mode IPS
IPS v5.02-24
2
If the traffic matches a signature,
the signature fires.
Switch
32
The sensor can send an alarm
to a management console and
take a response action such as
resetting the connection.
Sensor
Management
System
2005 Cisco Systems, Inc. All rights reserved.
Target
IPS v5.02-25
Sensor
An alert can be
sent to the
management console.
Management
System
2005 Cisco Systems, Inc. All rights reserved.
If a packet triggers a
signature, it can be
dropped before it
reaches its target.
Target
IPS v5.02-26
Reliable IPS
IPS software contains several features that
enable you to use inline deny actions with
confidence. Among these features are the
following:
Risk rating
Software bypass mode
Application firewall
Meta event generator
IPS v5.02-27
IPS v5.02-28
Network IPS
Sensors are connected to network segments. A
single sensor can monitor many hosts.
Growth of a network is easily protected. New hosts
and devices can be added to the network without
additional sensors.
The sensors are network appliances tuned for
intrusion detection analysis.
The operating system is hardened.
The hardware is dedicated to intrusion detection
analysis.
IPS v5.02-29
Firewall
Switch
Switch
Router
Untrusted
Network
Sensor
Management
Server
IPS v5.02-30
IPS v5.02-31
Agent
Agent
Application
Server
Firewall
Untrusted
Network
Agent
Agent
Agent
Agent
SMTP
Server
Agent
Console
Agent
Agent
WWW DNS
Server Server
IPS v5.02-32
Application-level encryption
protection
Host-Focused
Technology
IPS v5.02-33
Sensor Deployment
IPS v5.02-34
IPS v5.02-35
Router Firewall
Untrusted
Network
Sensor
IDSM2
Management
Server
Sensor
CSA Agent
WWW
Server
2005 Cisco Systems, Inc. All rights reserved.
CSA Agent
DNS
Server
IPS v5.02-36
Internet
Sensor on Outside:
Sensor on Inside:
Requires immediate
response to alarms
IPS v5.02-37
IPS Terminology
IPS v5.02-38
IPS v5.02-39
False Alarms
False positive: Normal traffic or a benign action
causes the signature to fire.
False negative: A signature is not fired when
offending traffic is detected. An actual attack is not
detected.
IPS v5.02-40
True Alarms
True positive: A signature is fired properly when
the offending traffic is detected. An attack is
detected as expected.
True negative: A signature is not fired when
nonoffending traffic is detected. Normal traffic or a
benign action does not cause an alarm.
IPS v5.02-41
IPS v5.02-42
IPS v5.02-43
IPS v5.02-44