Richard Bejtlich Sticks Up For IDS. I Retaliate.
Thomas Ptacek | October 28th, 2006 | Filed Under: Industry Punditry, Uncategorized
Richard Bejtlich pulls another DailyDave thread into his blog, irritated by the security community’s dismissal of intrusion detection. Couple things.
We Get To Talk About IDS, Richard
Richard Bejtlich does not get to dismiss Dave Aitel and Halvar Flake as “offensive computing” experts who don’t understand IDS, and, personally, if he calls me an “offensive computing” person again I’m going to ask for an apology. Richard, these people are your peers, and you read DailyDave for the same reason I do: it’s an excellent list.
It’s Not About Signatures
The IDS/IPS problem, which is now a decade old, is that lots of smart people in operations, research, and development are skeptical that it works at all. You cannot bait your way out of this problem by saying “that’s just signature IDS”. Sorry, Richard, I know how Bro works and I’m pretty familiar with anomaly detection. These ideas have, if anything, amplified the fundamental signal/noise problem “attack detection” creates.
Does Anyone Actually Rely on IPS?
On DailyDave, I asked the same simple question I always ask about IPS:
“I am waiting for someone to tell me the story about how an IDS saved their bacon. I’m not interested in the story about how it found the guy with the spyware infection or the bot installation; secops teams find those things all the time in their firewall logs and they don’t freak out about it when they do.”
Richard says, “it saved my bacon all the time at Ball Aerospace”. Alright, Richard, now tell us a story. And if the story ends in “so I scrubbed the infection off the desktop and nobody ever had to think about it again”, please find another story.
What Are These “Great Ideas” In IDS People Talk About?
I made a somewhat inflammatory point:
“Intrusion detection has been an active field of research for over 15 years now and apart from Tripwire I can’t point to anything operationally valuable it has produced.”
This should be an easy one to knock down. But all you say is, “this sounds like the ‘Snort is worthless’ argument”. You’re a smart guy who thinks about this stuff all the time, Richard. Can you actually address the argument I really made? I know a whole bunch of my readers can (and probably will, with expletives).
Firewalls and IDS Are Not Comparable
IDS is not “pigeonholed the same way firewalls are”. There’s a difference: firewalls are hugely successful, perhaps the single most important piece of security technology enterprises buy. It is absolutely unimaginable for a large company to be connected to the Internet without them. You cannot say the same thing about IDS/IPS; lots of enterprises don’t use it, and they aren’t suffering.
ps: the stuff about tape drive speed? that was a joke. about tape drives.
10/28: NB: We have lots of very talented friends who are real believers in monitoring and even IDS; some of them are talking here, some of them on DailyDave, and doubtless some are just reading and shaking their heads. I don’t think any less of any of these people, including Richard, because they buy the IPS story and I don’t. But I have an opinion and intend to be ruthless about transmitting it.


Add New Comment
Viewing 18 Comments
Thanks. Your comment is awaiting approval by a moderator.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Add New Comment
Trackbacks