Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

IDS and Network Taps

Thread Tools
 
Search this Thread
 
Old 08 March 2002, 10:32 AM
  #1  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Post

Has anyone used Network Taps for intrusion detection systems?

How did they implement these?
Old 08 March 2002, 10:47 AM
  #2  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

I have...what do you want to know?


Jeff
Old 08 March 2002, 10:53 AM
  #3  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Post

I'm deploying them with ISS RealSecure - have you used that? It basically has a function called RSKILL which sends TCP Resets to kill suspecious connections - can I have such a setup which would allow me to inject packets back into the network, given that they are passively monitored from taps?

Also, did you run these taps off a SPAN port for each network segment?

DO you have any (sanitised) docs or links that may may give more details?

Many thanks!
Old 11 March 2002, 12:27 PM
  #4  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

I am looking at implementing Intrusion detection software on our network, is iss one of the best?

Is this the sort of thing to prevent internal attacks as well??

David
Old 12 March 2002, 09:33 AM
  #5  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Post

David,

ISS is very good - can't say if its the best - there are plenty of IDS comparisons on the net.

Security is a process entailing prevention, detection and response - so the operations/monitoring of IDS software is paramount to it's effectiveness - and this tends to be product-independant.

If you would like to know any specifics about ISS - pro's and con's, just ask here.
Old 12 March 2002, 09:40 AM
  #6  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Post

Jeff,

Sorry for the confusion before re. Network taps. I didn't explain it well.

Basically, the taps will run off the main segments and the mirrored ports (from the taps) will go directly into a cisco switch. This switch will have a SPAN port which will be connected to a network sensor. The problem is getting the network sensor to send RSKILLs back on to the LAN segments.

How could I do this given the that RSKILLs are infact layer 3 packets disguised as layer 2's.

Cheers!
Old 12 March 2002, 01:56 PM
  #7  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Hi

Why don't you give me a shout on 01892 839901 or we'll be posting here for ever....!


Jeff

Trending Topics

Old 03 August 2002, 11:39 AM
  #8  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Firstly RSKILL is a dangerous function because you actually give away the fact that your using RealSecure, it can also turn into the worlds greatest denial of service attack if configured incorrectly. When I set-up a RealSecure system I always set it to drop the connection rather than kill it.

The tap issue is interesting. You either use a span port or a tap, you don't need to do both. If you want maximum performance you need to use a TopCall switch which is supported by ISS.

There are a bunch of documents on the ISS site which detail what you want to do. If you need any more help e-mail me.


Cheers

Jeff

[Edited by Jeff Wiltshire - 3/8/2002 11:41:38 AM]
Old 03 November 2002, 05:01 PM
  #9  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

YHM

err... David, your e-mail address in your profile bounced ?


Jeff

[Edited by Jeff Wiltshire - 3/11/2002 5:20:18 PM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JimBowen
ICE
5
02 July 2023 01:54 PM
greg320
Non Car Related Items For sale
6
11 October 2015 11:44 AM
skoobidude
Non Scooby Related
11
15 September 2015 09:50 PM
johnfelstead
ScoobyNet General
27
26 February 2001 05:48 PM
IWatkins
ScoobyNet General
1
24 October 2000 10:46 AM



Quick Reply: IDS and Network Taps



All times are GMT +1. The time now is 11:33 AM.