Types of IDS and IPS Sensors

Advantages

Disadvantages

• Easy configuration

• Fewer false positives

• Good signature design

• No detection of unknown signatures

Signature-Based

• Initially a lot of false positives

• Signatures must be created, updated, and tuned

Policy-Based

• Simple and reliable

• Customized policies

• Can detect unknown attacks

• Generic output

• Policy must be created

Anomaly-Based

• Easy configuration

• Can detect unknown attacks

• Difficult to profile typical activity in large networks

• Traffic profile must be constant

Honey Pot-Based

• Window to view attacks

• Distract and confuse attackers

• Slow down and avert attacks

• Collect information about attack

• Dedicated Honey pot server

• Honey pot server must not be trusted

The table in the figure summarizes the advantages and disadvantages of the various types of IDS and IPS sensors available. The list here describes these IDS and IPS sensors in more detail.

■ Signature-based: A signature-based IDS or IPS sensor looks for specific, predefined patterns (signatures) in network traffic. It then compares the traffic to a database of known attacks and triggers an alarm or prevents communication if a match is found. The signature may be based on a single packet or a sequence of packets. New attacks that do not match a signature will not result in detection. For this reason, the signature database needs to be constantly updated.

Note Protocol analysis-based intrusion detection is similar to signature-based intrusion detection,

but it performs a more in-depth analysis of the protocols specified in the packets.

Signature-based pattern matching is an approach that is rigid but simple to employ. In most cases, the pattern is matched against only if the suspect packet is associated with a particular service or, more precisely, destined to and from a particular port. This helps to lessen the amount of inspection done on every packet. However, it tends to make it more difficult for systems to deal with protocols that do not reside on well-defined ports and, in particular, Trojan horses and their associated traffic, which can usually be moved at will.

At the initial stage of incorporating signature-based IDS or IPS, before the signatures are tuned there can be a lot of false positives (traffic generating an alert which is no threat for the network). After the system is tuned and adjusted to the specific network parameters there will be fewer false positives than with the next approach, the policy-based approach.

5-10 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

■ Policy-based: The IDS or IPS sensor is preconfigured based on the network security policy. You must create the policies used in a policy-based IDS or IPS. Any traffic detected outside the policy will generate an alarm or will be dropped. Creating a security policy requires detailed knowledge of the network traffic and is a time-consuming task. Policy-based signatures use an algorithm to determine if an alarm should be fired. Often policy-based signature algorithms are statistical evaluations of the traffic flow. For example, in a policy-based signature that is used to detect a port sweep, the algorithm issues an alarm when the threshold number of unique ports is scanned on a particular machine. Policy-based signature algorithms could be designed to only analyze a specific type of packets, for example, SYN packets. The policy itself may require tuning. For example, you might have to adjust the threshold level of certain types of traffic so that the policy conforms to the utilization patterns on the network that it is monitoring. Polices may be used to look for very complex relationships.

■ Anomaly-based: Anomaly-based or profile-based signatures typically look for network traffic that deviates from what is seen "normally." The biggest issue with this methodology is that you first need to define what "normal" is. Some systems have hard-coded definitions of normal traffic patterns and, in this case, they could be considered heuristic-based systems.

Other systems are built to learn normal traffic behavior; however, the challenge with these systems is in eliminating the possibility of improperly classifying abnormal behavior as normal. Also, if the traffic pattern being learned is assumed to be normal, the system must contend with how to differentiate between allowable deviations and those deviations not allowed or that represent attack-based traffic. Normal network traffic can be difficult to define.

■ Honey pot-based: Honey pot systems use a dummy server to attract attacks. The purpose of the honey pot approach is to distract attacks away from real network devices. By staging different types of vulnerabilities in the honey pot server, you can analyze incoming types of attacks and malicious traffic patterns. You can use this analysis to tune your sensor signatures to detect new types of malicious network traffic.

© 2006 Cisco Systems, inc. Securing Networks with Cisco iOS IPS 5-11

Continue reading here: Recommended approaches to implementing multiple IDS management consoles

Was this article helpful?

+11 -4

Readers' Questions

  • Gabriele Russo
    What is an ids and ips?
    1 month ago
  • IDS stands for Intrusion Detection System. It is a security tool or software that monitors network traffic, systems, and applications to detect and identify any suspicious or malicious activities. IDS typically analyzes network packets, logs, or system events to identify indicators of potential threats or attacks. IPS stands for Intrusion Prevention System. It is a security tool or software that not only detects but also actively blocks or prevents potential threats or attacks. IPS goes beyond the detection capabilities of IDS and actively takes actions to mitigate security risks by blocking suspicious network traffic or applying other protective measures. In summary, IDS is focused on detecting and providing alerts for potential security breaches, while IPS is designed to not only detect but also actively prevent such breaches by taking immediate actions.
    • Prisca Arcuri
      What behaviors might trigger an alert in an ids/ips?
      2 months ago
      1. Unauthorized port scans by external hosts.
      2. Network packets with suspicious payloads.
      3. Multiple failed login attempts.
      4. Large amounts of traffic from a single IP address.
      5. Incoming and outgoing traffic from suspicious IPs.
      6. Abnormal traffic patterns.
      7. Anomalous activities on the network.
      8. Brute force attacks.
      9. Distributed Denial-of-Service (DDoS) attacks.
      10. Malware or virus communications.
      • lennox
        How does an ips differ from an ideas?
        3 months ago
      • An IPS (Intellectual Property Strategy) is a plan or strategy that a company or organization uses to protect, maintain and leverage its proprietary intellectual property assets. It outlines how to protect intellectual property from theft or misuse, how to recognize its value, how to benefit from it, how to manage its risks, how to promote its development and how to develop new IP assets. An IDEA (Inventive Design for Economic Advancement) is a plan or strategy that a company or organization uses to develop and promote innovative products, services, and processes. This strategy focuses on the creation of new ideas and solutions, the assessment of their viability, and the commercialization of the solutions. It emphasizes a focus on research, development, and marketing in order to bring novel solutions to the marketplace.
        • aedan
          Which monitoring methodology will trigger the ids if any application tries to scan multiple ports?
          4 months ago
        • in a network A network-based intrusion detection system (NIDS) would be able to detect and alert on any application that is scanning multiple ports in a network. It monitors network traffic in real-time and can detect suspicious activity such as port scans, buffer overflows, denial of service attacks, and more.
          • dwight
            What two sensors does the network based idps use?
            5 months ago
          • ? The two sensors used in a network based Intrusion Detection and Prevention System (IDPS) are a network sensor and a host sensor. The network sensor detects intrusion attempts and malicious activities by monitoring network traffic, while the host sensor inspects the activities of individual hosts on the network and looks for malicious activities.
            • odo
              What are sensors in ids ips tipping point?
              5 months ago
            • Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) sensors are hardware or software solutions that detect and/or prevent malicious activities on a network. They analyze network traffic and/or system activity and detect potential intrusions or malicious activity. A Tipping Point refers to a situation in which a small change can cause a large, often unpredictable effect. In the context of IDS and IPS systems, it is a critical point at which an intrusion occurs and the proper countermeasures are taken to prevent further infiltration.
              • berilac
                What are the drawback of signature based ids?
                7 months ago
                1. Signature-based IDSs are limited to detecting previously known attacks. They can’t detect new or unknown threats.
                2. These systems can create many false alarms if the signature definitions of the IDS are not tuned properly. This requires manual effort and can be very time-consuming.
                3. Signature-based IDSs can only detect malicious activity, they cannot prevent it.
                4. They can easily miss certain types of attacks, such as attacks that use fragmented packets.
                • PEONY GREENHAND
                  Which of the following is the definition of patternbased ids?
                  8 months ago
                • Pattern-based IDS is an Intrusion Detection System that uses patterns or signatures, which are known attack patterns or suspicious activity, to detect and alert administrators of malicious behavior.
                  • Simon
                    Which ids/ips signature alarm will look for packets that are destined to or from a particular port?
                    8 months ago
                  • The IDS/IPS signature alarm will look for packets that contain the destination port number or the source port number.
                    • Ronan
                      Do ips sensors learn on their own?
                      1 year ago
                    • No, IPS sensors do not learn on their own. They rely on manual configuration and rulesets to detect suspicious activity.
                      • negassi
                        Is a ips sensor just an ips device?
                        1 year ago
                      • No, an IPS sensor is not just an IPS device. An IPS sensor is a type of Intrusion Prevention System (IPS) device that uses advanced algorithms to detect and prevent malicious network traffic or activities.
                        • kiros
                          What are cisco wlc ids sensors?
                          1 year ago
                        • Cisco Wireless LAN Controllers (WLCs) IDS sensors detect and act on malicious and unauthorized activity on the wireless networks of organizations. They use signature-based intrusion detection which is signature-based, which means they recognize patterns in the network traffic. They can also detect rogue access points and measure signal strength to detect suspicious activity. They allow for a centralized management of the wireless network and provide detailed reports and analysis on detected malicious activity.
                          • UTA
                            What type of IDS is the CISCO sensor?
                            1 year ago
                          • Cisco Sensor is an Intrusion Detection System (IDS).
                            • remigio
                              What is ips sensor trigger?
                              1 year ago
                            • An IP (Intrusion Prevention) Sensor Trigger is an alert or warning that indicates an attempted security breach on a network. It is typically created by an intrusion detection system (IDS) or an intrusion prevention system (IPS). Trigger events can range from a scan of a specific port to attempts to exploit a known vulnerability.
                              • john
                                What two sensor types exist in an ids/ips solution?
                                1 year ago
                                1. Network intrusion detection sensors (NIDS)
                                2. Host intrusion detection sensors (HIDS)