Cisco Secure IDS Sensors
An IDS sensor can exist in one of two forms: a dedicated hardware device, or a software agent that resides on a specific host. The hardware version of the sensor is directly connected to a segment of the network that requires monitoring, whereas the software version resides on each specific host that requires monitoring.
These two types of IDS sensor give rise to what is commonly called network IDS (NIDS) and host IDS (HIDS), respectively. A NIDS is designed to support multiple hosts and uses hardware sensors, whereas a HIDS is set up to detect illegal actions within a single host and uses the software-based sensor. Figure 11-2 shows the deployment of the two types of IDS sensors.
Figure 11-2 Typical NIDS and HIDS Deployment
Figure 11-2 Typical NIDS and HIDS Deployment
Cisco Secure NIDS and HIDS sensors are discussed in the following two sections.
Cisco Secure NIDS sensors
The Cisco Secure NIDS sensors are the muscle in the Cisco Secure IDS solution and consist of hardware appliances that are tuned for optimum performance and ease of maintenance.
NOTE Limited IDS capability is now available in many Cisco router platforms and in the Cisco Secure PIX Firewall Series.
Sensors constantly monitor network traffic in real time while looking for distinctive attack patterns in the traffic flow. Each sensor checks network traffic for a pattern match against one of the attack signatures in its signature database. This monitoring occurs through a specific monitoring interface on the sensor, whereas alarms are transmitted through the command and control interface to the management console.
When a traffic pattern triggers a signature response, the sensor logs the event and sends an alarm to the management console. The sensor also has several response options available that it can initiate when it detects an attack. These options are outlined in Table 11-2.
|
Response Action |
Response Description |
|
Alarm |
Sensor reports the event to the Director (this occurs by default). |
|
Sensor terminates the individual TCP connection if it senses that it has been involved in an attempted or actual attack. |
|
|
IP blocking (shunning) |
Sensor can automatically reconfigure an ACL on a router to block the attacker at the perimeter. |
|
IP logging |
Sensor records a log of the attacker's activities. This is a passive event and allows the attacker to continue. |
Table 11-3 describes the Cisco IDS NIDS sensors that are currently available.
|
Model |
Performance (Mbps) |
Response |
Signature Coverage |
|
4210 |
45 |
Reset, shun, and log |
Full |
|
4235 |
100 |
Reset, shun, and log |
Full |
|
4250 |
100 |
Reset, shun, and log |
Full |
|
IDSM |
260 |
Shun |
Full |
Cisco Secure HIDS Sensors
The Cisco Secure HIDS sensor is a software agent that resides on the specific host that it is intended to monitor and protect. It safeguards the entire server by preventing known and unknown attacks. It uses a combination of behavioral rules and signatures to prevent attacks, rather than merely detecting and reporting them after they occur.
Currently, two versions of the Cisco Secure HIDS sensor are available: a Standard Edition Agent and a Server Edition Agent. Their functionality is shown in Table 11-4.
|
Agent Edition |
Placement |
Functionality |
|
Standard |
Hosts |
Protects by evaluating requests to the operating system before they are processed |
|
Server |
Includes the Standard Edition functionality but also protects the web server application and the web server API |
The Standard Edition Agent is leveled for general host use. The Server Edition Agent, however, is aimed at public-facing devices, such as web servers, which require additional levels of security because of increased vulnerabilities.
Continue reading here: Designing Medium Sized SAFE Networks
Was this article helpful?