Network Based Intrusion Detection Systems
Network-based intrusion detection systems are physical devices that are connected to various network segments within the protected network. Network-based intrusion detection systems usually comprise two components that work together to provide the IDS service. These two components are an IDS sensor (Cisco's is the Intrusion Detection Sensor) and an IDS management platform (Cisco's is the Intrusion Detection Director).
The IDS sensors are hardware devices that passively monitor and analyze the traffic flow within a network segment. The sensor monitors the traffic and compares the collected data to prebuilt IDS signatures, to build up a profile of activity on the network segment. One problem with the IDS sensors is their placement. They can only monitor traffic that their network connection sees. The network interface listens in promiscuous mode to process all network traffic, even that not destined for the sensor itself. The obvious problem is that a normal switch port creates a separate collision domain and a shared broadcast domain throughout the VLAN to which the switch port is connected. Therefore, the sensor only receives unicast traffic destined for the sensor itself and broadcast traffic on that VLAN. To get around this, you should connect the IDS sensor to what is called a Switched Port Analyzer (SPAN) port on the switch. SPAN ports can be configured on all of the Cisco Catalyst range of switches. A SPAN port can be configured to listen to all unicasts and broadcasts for specific VLANs on one port.
This is ideal for the IDS sensor. as it can then passively monitor and analyze all unicast traffic on the network segment across multiple VLANs. Figure 6-2 shows a network-based intrusion detection system.
Figure 6-2. Network-Based Intrusion Detection
Figure 6-2. Network-Based Intrusion Detection

- management platform. The IDS sensor sends notification messages to the IDS management platform, which can be configured to interpret these results and take necessary action on them.
Intrusion Detection Systems
Now that you have a brief explanation of intrusion detection. the remainder of this chapter covers the current intrusion detection offerings from Cisco Systems. There are three main offerings from Cisco across differing platforms:
• Cisco Secure Intrusion Detection System (CSIDS)
• Cisco IOS Firewall IDS
• Cisco Secure PIX Firewall IDS
Cisco Secure Intrusion Detection System (CSIDS)
Most of this book focuses on ways to prevent outside unauthorized entities from connecting to your network. This section differs in that the focus is on how patterns of abuse are detected from both internal and external sources. After a pattern of abuse is noted, you can respond in real time to the threat. The phrase patterns of abuse is used because the Cisco Secure Intrusion Detection System (CSIDS) looks at the format and the amount of data traversing your network to determine the likelihood and severity of threats. The patterns within the data traversing the network are analyzed to determine whether an attack has been launched.
This section covers the CSIDS. The CSIDS is differentiated from the Cisco IOS Firewall IDS and the Cisco Secure PIX Firewall IDS in that the CSIDS is designed to run both independently and in conjunction with the existing hardware on a network. Additionally, the abilities of the CSIDS to detect and respond to threats are much greater than those built into either the Cisco IOS Firewall or the Cisco Secure PIX Firewall. These additional abilities are available because routing or performing firewall functions is not the main purpose of the CSIDS. The main purpose of the CSIDS is to detect and respond to patterns of abuse in real time.
A full explanation of the details of installation, maintenance, and configuration of the CSIDS is beyond the scope of this book. However, this section gives you the theory necessary to begin your investigations into the CSIDS. This section provides an overview of the most important features and issues involved with the CSIDS, the basics of Sensor deployment, Director deployment, signatures, alarms, and log files.
Intrusion detection monitors against three forms of attack.
• Reconnaissance attacks— A reconnaissance attack is where an attempt is made to discover and map services, vulnerabilities, and systems for purposes of later access or denial of service (DoS) attacks. As little information about your network should be revealed as possible, because excessive revelations might show possible weaknesses that have not yet been addressed. For example, an internal user might scan the ports on a server to prepare for breaking into that server for confidential information.
• Access attacks— An access attack occurs when users actively attempt to access services to which they do not have authority. For example, an internal user sitting at a desk and repeatedly trying to log into a server with another user's name and different passwords is considered an access attack.
• Denial of service (DoS) attacks— A DoS attack occurs when an attempt is made to prevent valid use of a network or system. Many examples of DoS attacks, including the ping of death attack, are discussed throughout this book.
The CSIDS is designed to monitor for these types of attack and to notify the appropriate personnel in the event of such an attack. Logs are built that detail the suspicious packets. The CSIDS can also respond by denying service to the perpetrators of all three forms of attack.
Cisco has chosen to implement a packet-based detection method to determine when an attack is in progress. This method relies on comparing the data within each packet with a "signature" that indicates a possible attack. There are some differences between the signatures used within the Cisco IOS software used on routers and those found on the Cisco IDS equipment. One difference is the number of signatures: although the Cisco IOS has implemented 59 signatures and the PIX Firewall has implemented 57 signatures, the CSIDS has a much larger number of signatures. Additionally, CSIDS allows a skilled administrator to create new signatures. This allows the protection of the network to evolve as new threats emerge.
The CSIDS was formerly called NetRanger, and many of the existing URLs on the Cisco web site still refer to this product with the old name. Keep the old name in mind when searching the Cisco web site for specific information about the CSIDS.
Continue reading here: Signature Severity Levels
Was this article helpful?
Readers' Questions
-
Reginard Goodchild7 months ago
- Reply