<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IPS Guy &#187; IPS</title>
	<atom:link href="http://theipsguy.com/tag/ips/feed/" rel="self" type="application/rss+xml" />
	<link>http://theipsguy.com</link>
	<description>Intrusion Prevention/Detection technologies.</description>
	<lastBuildDate>Sun, 13 May 2012 00:37:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Virtual IPS vs. Virtualized IPS</title>
		<link>http://theipsguy.com/virtual-ips-vs-virtualized-ips/</link>
		<comments>http://theipsguy.com/virtual-ips-vs-virtualized-ips/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 17:48:14 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Sourcefire]]></category>
		<category><![CDATA[Virtual IPS]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=223</guid>
		<description><![CDATA[Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions. The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions.</p>
<p>The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to attempt to differentiate these terms. Most vendors have had virtual IPS for many years. Virtual IPS is the ability to apply different polices to certain types of traffic. This could be done using VLAN tags or physical interfaces. IBM does this using the Protection Domains feature which allows a different policy to be deployed to different VLAN&#8217;s. Mcafee does this by allowing different policies to be assigned to physical interfaces and can also support policies to be applied based no VLAN tags.</p>
<p>Virtualized IPS is what most of us think of today when we discuss virtualization. Virtualized IPS is an IPS appliance that runs in a virtual environment such as VmWare, Zen or Microsoft&#8217;s Hyper-V. The IPS is installed as a virtual server and can be configured so that all server to server traffic inside and outside the virtual environment can be monitored by an IPS.</p>
<p>It is important to be clear on these differences in terminology because not all vendors have virtualized IPS and most sales people will not know enough to properly answer the question, Do you support virtualization? Most will say yes, because they have heard their support teams talk about virtual IPS not virtualized IPS. Virtualized IPS will continue to grow in importance and eventually all the major Intrusion Prevention vendors will have these offerings. Until then do your homework and hold the vendors accountable.</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/virtual-ips-vs-virtualized-ips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forrester Network Mitigation Report</title>
		<link>http://theipsguy.com/forrester-network-mitigation-report/</link>
		<comments>http://theipsguy.com/forrester-network-mitigation-report/#comments</comments>
		<pubDate>Sat, 26 Sep 2009 21:07:05 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[IDS vulnerabilities.]]></category>
		<category><![CDATA[Mcaffe]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=24</guid>
		<description><![CDATA[I recently read the TechRadar for Security &#38; Risk Professionals: Network Threat Mitigation, Q3 2009 by Forrester. This report reviewed 14 different threat mitigation categories. These included encryption, wireless IDS/IPS, UTM, Intrusion prevention, network access control,Web-content filtering and a few others. It is obvious that the bad guys are highly organized and very skilled. The [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<h6>I recently read the TechRadar for Security &amp; Risk Professionals: Network Threat Mitigation, Q3 2009 by Forrester. This report reviewed 14 different threat mitigation categories. These included encryption, wireless IDS/IPS, UTM, Intrusion prevention, network access control,Web-content filtering and a few others.</h6>
<h6>It is obvious that the bad guys are highly organized and very skilled. The number and sophistication of attacks do not seem to be going down but instead increasing. Forrester identified three areas they see in their client companies:</h6>
<ol>
<li>
<h6>The current controls are either not able to prevent the type of threats we see today of the solutions and how they are used need to be re-thought.</h6>
</li>
<li>
<h6>Companies fear inline protection. Even though many companies have successfully deployed Intrusion Prevention, there is a general fear the IPS will block legitimate traffic.</h6>
</li>
<li>
<h6>Companies lack visibility into what is really happening on their networks. This is somewhat by design because what you do not know you do not have to address.</h6>
</li>
</ol>
<h6>Forrester did a good job of grouping the type of technologies and providing a ranking on their business value. I agree in general with their assessments.</h6>
<table style="height: 302px;" border="1" cellspacing="0" cellpadding="2" width="400">
<tbody>
<tr style="text-align: center;">
<td width="200" valign="top">
<h6><strong>Technology</strong></h6>
</td>
<td width="198" valign="top">
<h6><strong>Business Value</strong></h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Firewall Auditing</h6>
</td>
<td width="198" valign="top">
<h6>Low</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Network Encryption</h6>
</td>
<td width="198" valign="top">
<h6>Negative</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Network Threat Modeling</h6>
</td>
<td width="198" valign="top">
<h6>Negative</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Network Access Control</h6>
</td>
<td width="198" valign="top">
<h6>Low</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>UTM</h6>
</td>
<td width="198" valign="top">
<h6>Low</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Email Security Gateway</h6>
</td>
<td width="198" valign="top">
<h6>High</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Network Firewall</h6>
</td>
<td width="198" valign="top">
<h6>High</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Vulnerability Scanners</h6>
</td>
<td width="198" valign="top">
<h6>Medium</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>NBAD</h6>
</td>
<td width="198" valign="top">
<h6>Negative</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>IDS</h6>
</td>
<td width="198" valign="top">
<h6>Negative</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>IPS</h6>
</td>
<td width="198" valign="top">
<h6>High</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Web Proxy</h6>
</td>
<td width="198" valign="top">
<h6>Medium</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Application Firewalls</h6>
</td>
<td width="198" valign="top">
<h6>Low</h6>
</td>
</tr>
<tr>
<td width="200" valign="top">
<h6>Wireless IDS/IPS</h6>
</td>
<td width="198" valign="top">
<h6>Medium</h6>
</td>
</tr>
</tbody>
</table>
<h6>Forrester states that NBAD is declining and will be replaced with and NBA. Further they predict NBA will likely be added to other security appliances. I agree with this assessment and vendors are working hard to integrate NBA into their Intrusion Prevention systems. Mcafee will be doing this soon as well as IBM/ISS and Cisco already does this.</h6>
<h6>One item I noticed and this is likely a mistake on the part of the authors is that they listed Snort/Sourcefire in the IDS only category.  While I agree with the general categorization of Snort as an IDS only I do not agree with Sourcefire being in this category and I doubt Martin Roesch would either.</h6>
<h6>Forester rates Network Intrusion Prevention as a High business value and I would of course tend to agree but I may be a little biased.  They see their clients replacing older IDS based systems with IPS and relying on this technology as a key control in their network.  Many vendors are beginning to add other features to their IPS devices. Companies like IBM/ISS have limited DLP functionality in their network intrusion prevention devices and IBM/ISS recently released  web application firewall functionality.</h6>
<h6>Network Intrusion Prevention continues to be a key control used by businesses and is only going to continue to grow. I believe we will see IPS become a platform for more services like DLP and NBA similar to how firewalls have integrated IPS, content filtering and other technologies.</h6>
<div id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:de89756d-8fcf-442f-a266-a11e598f37b7" class="wlWriterEditableSmartContent" style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px">
<h6>Technorati Tags: <a rel="tag" href="http://technorati.com/tags/intrusion+prevention+wireless+intrusion+prevention">intrusion prevention wireless intrusion prevention</a></h6>
</div>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/forrester-network-mitigation-report/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>September Microsoft Bulletins</title>
		<link>http://theipsguy.com/september-microsoft-bulletins/</link>
		<comments>http://theipsguy.com/september-microsoft-bulletins/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 13:27:00 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[Microsoft Security Bulletins]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[XPU]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=1</guid>
		<description><![CDATA[IBM/ISS Coverage http://bit.ly/11xX5Q MS Bulletin Coverage Coverage Date MS09-049 Scanner Only 1.59 September, 8 th 2009 MS09-048 XPU&#8217;s 20.90, 1.71, 1.72, 28.010,28.150,29.130, 29.030,29.070,29.080 Multiple dates of coverage. 2006, 2008, 2009 MS09-047 XPU 20.90 September, 8 th 2009 MS09-046 XPU 20.90 September, 8 th 2009 MS09-045 XPU 20.90 September, 8 th 2009 Cisco http://bit.ly/R1LEj MS Bulletin [...]]]></description>
			<content:encoded><![CDATA[<p></p><div>
<p style="margin-bottom: 0in;"><strong>IBM/ISS Coverage</strong></p>
<p style="margin-bottom: 0in;"><strong><a href="http://bit.ly/11xX5Q">http://bit.ly/11xX5Q</a></strong></p>
<table style="width: 339px; height: 384px;" border="1" cellspacing="0" cellpadding="4" bordercolor="#000000">
<col width="154"></col>
<col width="154"></col>
<col width="422"></col>
<tbody>
<tr valign="top">
<td width="154"><strong>MS Bulletin</strong></td>
<td width="154"><strong>Coverage</strong></td>
<td width="422"><strong>Coverage Date</strong></td>
</tr>
<tr valign="top">
<td width="154">MS09-049</td>
<td width="154">Scanner Only 1.59</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-048</td>
<td width="154">XPU&#8217;s 20.90, 1.71, 1.72, 28.010,28.150,29.130,</p>
<p>29.030,29.070,29.080</td>
<td width="422">Multiple dates of coverage. 2006, 2008, 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-047</td>
<td width="154">XPU 20.90</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-046</td>
<td width="154">XPU 20.90</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-045</td>
<td width="154">XPU 20.90</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
</tbody>
</table>
<p style="margin-bottom: 0in;"><strong>Cisco</strong></p>
<p style="margin-bottom: 0in;"><a href="http://bit.ly/R1LEj"><strong>http://bit.ly/R1LEj</strong></a></p>
<table style="width: 341px; height: 209px;" border="1" cellspacing="0" cellpadding="4" bordercolor="#000000">
<col width="154"></col>
<col width="154"></col>
<col width="422"></col>
<tbody>
<tr valign="top">
<td width="154"><strong>MS Bulletin</strong></td>
<td width="154"><strong>Coverage</strong></td>
<td width="422"><strong>Coverage Date</strong></td>
</tr>
<tr valign="top">
<td width="154">MS09-049</td>
<td width="154">NA</td>
<td width="422"></td>
</tr>
<tr valign="top">
<td width="154">MS09-048</td>
<td width="154">S430, S248, S431, S242</td>
<td width="422">Multiple dates of coverage</td>
</tr>
<tr valign="top">
<td width="154">MS09-047</td>
<td width="154">S431</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-046</td>
<td width="154">S431</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-045</td>
<td width="154">S431</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
</tbody>
</table>
<p style="margin-bottom: 0in;"><strong>Mcafee</strong></p>
<p style="margin-bottom: 0in;"><strong><a href="http://bit.ly/4w90TJ">http://bit.ly/4w90TJ</a></strong></p>
<table style="width: 339px; height: 419px;" border="1" cellspacing="0" cellpadding="4" bordercolor="#000000">
<col width="154"></col>
<col width="154"></col>
<col width="422"></col>
<tbody>
<tr valign="top">
<td width="154"><strong>MS Bulletin</strong></td>
<td width="154"><strong>Signature ID</strong></td>
<td width="422"><strong>Coverage Date</strong></td>
</tr>
<tr valign="top">
<td width="154">MS09-049</td>
<td width="154">Foundstone 7110</td>
<td width="422"></td>
</tr>
<tr valign="top">
<td width="154">MS09-048</td>
<td width="154">0x9E00, 7106</td>
<td width="422">September, 8 <sup>th</sup> 2009, September 9 <sup>th</sup>, 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-047</td>
<td width="154">7108, 7109, 0x40265D00,0x40265E00</td>
<td width="422">September, 8 <sup>th</sup> 2009, September 9 <sup>th</sup>, 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-046</td>
<td width="154">0&#215;40266900</td>
<td width="422">September, 8 <sup>th</sup> 2009</td>
</tr>
<tr valign="top">
<td width="154">MS09-045</td>
<td width="154">7098, 0&#215;40266800</td>
<td width="422">September, 8 <sup>th</sup> 2009, September 9 <sup>th</sup>, 2009</td>
</tr>
</tbody>
</table>
<p style="margin-bottom: 0in;">
</div>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/september-microsoft-bulletins/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Detecting bot-nets</title>
		<link>http://theipsguy.com/detecting-bot-nets/</link>
		<comments>http://theipsguy.com/detecting-bot-nets/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 10:52:00 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[IRC]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=4</guid>
		<description><![CDATA[We here a lot about the rise of organized crime and the sophistication of the attackers. While this is true, in many cases I still see amateurish type attacks. While reviewing an IPS I found the following messages. IPS still provides a great way to detect bot-nets and while there is an obvious problem on [...]]]></description>
			<content:encoded><![CDATA[<p></p><div>
<p style="margin-bottom: 0in;"><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p style="margin-bottom: 0in;">We here a lot about the rise of organized crime and the sophistication of the attackers. While this is true, in many cases I still see amateurish type attacks.</p>
<p style="margin-bottom: 0in;">While reviewing an IPS I found the following messages. IPS still provides a great way to detect bot-nets and while there is an obvious problem on this network these IRC connections are being blocked by the IPS.</p>
<p style="margin-bottom: 0in;">An interesting article related to this can be found  <a href="http://www.networkworld.com/newsletters/techexec/2009/082409bestpractices.html?hpg1=bn">here.</a></p>
<p style="margin-bottom: 0in;">IRC Messages</p>
<table style="width: 192px; height: 58px;" border="0" cellspacing="0" cellpadding="0">
<col width="36"></col>
<col width="139"></col>
<tbody>
<tr>
<td width="36" height="20">:nick</td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td width="139">:msg</td>
</tr>
<tr>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
</tr>
<tr>
<td height="20">#usb</td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td>Infected usb drive: E:</td>
</tr>
</tbody>
</table>
<p style="margin-bottom: 0in;">Interesting Nicknames to an IRC channel</p>
<p>VirUs-rigvgunl<br />
VirUs-rflkbvny<br />
VirUs-rexehaxz<br />
VirUs-rcpcmobp<br />
VirUs-rboinhcv<br />
VirUs-raquheuv<br />
VirUs-raozodkn<br />
VirUs-racgucrn<br />
VirUs-quyozuoc<br />
VirUs-qufnunld<br />
VirUs-msubtplz<br />
[03|MEX|XP|981734]<br />
[03|MEX|XP|444546]</p>
<p style="margin-bottom: 0in;">
</div>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/detecting-bot-nets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Welcome</title>
		<link>http://theipsguy.com/welcome/</link>
		<comments>http://theipsguy.com/welcome/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 11:39:00 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[IDS vulnerabilities.]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=9</guid>
		<description><![CDATA[Hello, This is the first post on the Intrusion Detection and Prevention blog. I plan to post information relating to these technologies, the vendors, etc. I hope you find it useful and interesting.]]></description>
			<content:encoded><![CDATA[<p></p><p>Hello,</p>
<p>This is the first post on the Intrusion Detection and Prevention blog. I plan to post information relating to these technologies, the vendors, etc. I hope you find it useful and interesting.</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/welcome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

