home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers







ISS RealSecure Pushes Past Newer IDS Players
May 17, 1999


How We Tested IDSes
While traditional IDS reviews have invoked packet blasters and broad-sweeping scans in an effort to simulate a "real" network, we dared to raise the bar a few levels. We put our IDSes on live, corporate production networks, and attacked from external, distributed points on the Internet. Rather than speculate on what type of traffic enterprise environments experience, we simply operated in one. Though our first instinct was to run a gamut of attacks--every exploit script, denial-of-service attack and probe utility we could get our hands on--we soon realized this type of haphazard onslaught wasn't entirely representative of actual threats.

IDSes should be able to accurately detect, and in some cases defend against, a range of common attacks, but their added value stems from their informational and procedural capabilities. They need to function and identify attacks properly, but more important, they need to be able to aid the administrator in operating a secure environment. Keeping this as the focus, we crafted test procedures that demonstrated both novice and experienced hacking skills.

Because some of our brute-force pummeling involved really nasty packet construction, we also conducted some tests in a closed lab environment. Using sets of home-brewed tools in conjunction with commercial products, such as Ganymede's Chariot, we built baseline traffic loads on the Ethernet segments and began hurling swarms of reconnaissance and exploit data across the wire.

Our attacks never originated from the target segment--all attacks traversed at least one router. Sensors were placed on the common (target) network segment allowing them equal access to the same traffic. Our initial runs were reconnaissance-based: We chose to use Fyodor's NMAP (see www.insecure.org), an incredibly useful tool for constructing anomalous packets and scans.

By playing with timing thresholds and scanning methods (syn, fin, xmas and null scanning) we could frequently avoid detection while still gaining valuable reconnaissance data. Although we used the data we obtained from watching alarm trends, an attacker could avoid detection simply by scanning conservatively. Without the ability to fine-tune thresholds, an attacker need only learn the default time-out values to do stealth reconnaissance.

Getting a little bolder, we moved to actual exploit scripts (such as FTP, IMAP and CGI holes), which were quickly identified by the IDSes that had matching signatures. Again, we were able to pull some newer exploits (a newer WU-FTPD hole, for example) that went undetected, a testament to the danger of relying on known problems.

Convinced of the basic functionality of identifying known signatures, we launched into denial of service (DoS). The most vicious DoS attack we used was winfreeze, which saturates the wire with millions of ICMP (Internet Control Message Protocol) redirect packets. The only system that caught this attack was NetRanger; the other IDSes crashed or ignored it. As suspected, each IDS identified most of the DoS attacks out there.

Leaving the realm of destruction and going into the real world, we focused on our live targets. We used what we knew about the scanning thresholds to map out the objective in stealth mode. Satisfied with our port scans, we began logging the "banners" of specific services, which helped us identify the versions and platforms of the targeted hosts. Because these connections appear as normal sessions, they went unflagged. Finally, using the knowledge gained from our reconnaissance efforts, success was a simple matter of finding and exploiting the weakest link. We pinpointed a hole in IIS and ripped out a local NT SAM. After brute-forcing the hashed passwords, we gleaned enough account information to authenticate to other machines without detection, and we were in.


Page 1 | 2 | 3 | 4 | 5 | 6 | 7 | First Page


Print This Page


e-mail E-mail this URL





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights