IDS: The integrated partner for your firewall

ANALYSIS
Firewalls alone are not enough to ward off today's more highly developed range of attacks. In fact, no single security method can truly detect or stop all attacks -- that is why many companies deploy multiple firewalls as additional security measures. Along those same lines, an Intrusion Detection System (IDS) is powerful tool that IT managers should consider in order to protect their information resources. In fact, IDS should be considered a part of your overall security strategy because it can provide proactive response protection (detect the attack and stop the attack). Let's take a look at IDS and see where it fits in to your network security plans. Coming from all sides
From Web vulnerabilities, which allow hackers to simply deface your Web site, to the theft of your most important asset, namely, your corporate data, attacks and intrusions are no longer limited to the outside world trying to get in -- they are coming from all sides. Because your firewall is deployed just inside your network, it is not concerned with the traffic that originates from within your company. I recently read about a project where a manufacturing company introduced older PCs, which were not fully patched or protected with current antivirus software, from another location into their main network. A Trojan horse program (Osprev) was immediately able to come alive and exploit the network system from within. It managed to find its way through the network connection and began DoS attacks on 20-plus other IP addresses. Why IDS?
There is no question that security vulnerabilities are increasing. Vulnerabilities reported by the CERT Coordination Center show that only 417 were reported in 1999. In the first three quarters of 2002, that figure was up to 3,222, a staggering increase of over 132 percent in vulnerabilities reported just within the past three years. This means that, more than ever, you need to be securing your system to the best of your abilities so that these vulnerabilities don't wreak havoc on your network. But, as a recent poll shows, not every one is doing as much as they can to secure their network. In fact, 38 percent of the respondents indicated they had not considered IDS, while 9 percent indicated that they had considered IDS but had decided against it. Through software bugs, exploiting protocol weaknesses, and cracking passwords, the dedicated hacker can track down and exploit any open door you have in your line of defense. Deploying an IDS could do a lot to close those doors. Your IDS solution protects your network assets by the following methods:
  • Accurately detecting attacks
  • Stopping the attack
  • Simplifying security management
  • Providing the proper documentation
  • Offering the flexibility needed to conform to your security policy
  • Double-checking incorrectly configured firewalls
  • Verifying that current security polices are in effect
  • Catching attacks that your firewall(s) legitimately allow through
  • Catching attempts that fail
  • Catching insider hacking
  • Detecting abnormal attacks from a terminal left unattended
  • Finding holes that intruders can exploit
  • Providing for documentation before, during, and after an attack
Where does IDS fit in?
Intrusion Detection Systems can be deployed at the point of insertion, behind the firewall, on various segments and servers, or in an array of locations as a comprehensive perimeter security guard. By monitoring traffic to safeguard your system from external and internal attacks on the network wire, the IDS system watches for and stops hackers attempting to break into your system. Detection methods include using attack signatures, checking for unusual protocol anomalies, and catching rogue processes. Types of detection systems
Hackers are constantly exploiting new vulnerabilities daily. By evolving new methods to gain access to your inner network, they launch new and sophisticated attacks that don't follow a set pattern. While signature-based detection is a solid system, protocol-anomaly detection can be used to identify the various attacks that do not follow normal patterns. Here are the types of detection systems should you consider for your IDS security solution:
  • Stateful signature detection
  • Protocol anomaly detection
  • Backdoor detection
It is your responsibility
As the technology evolves faster than patches can be distributed, there is a new worry that companies are potentially liable for damages caused by a hacker using their systems. You must be able to prove to a court that you took "reasonable" measures to defend yourself from hackers. More important, your data is now the most critical commodity you have to protect. The combination of the data available on the network systems and the compounded difficulties involved in protecting that data make internal user and Internet systems large, vulnerable targets. It is a common occurrence to see the media referring to intruder activities that result in financial loss, data corruption, and loss of public confidence. You have to ask yourself two questions: How much does downtime cost you, and how much will the loss of your data set you back? Ultimately, it is the due diligence of IT managers to bring to bear all technology (such as IDS) that they can to protect the corporate data they are entrusted with. For a weekly round-up of the enterprise IT news, sign up for the Enterprise newsletter. Tell us what you think in the Enterprise Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

9 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

12 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

14 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

19 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

1 day ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

2 days ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

2 days ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint