Figure 1011 Network Based IDS Sensor Placement

[View full size imagel

Placement Ids Network

Sensor 1, connected on the inside network, sees only traffic that is permitted by the firewall or internal traffic that does not traverse the firewall. All intrusions reported by Sensor 1 require immediate attention and response from the network administrator. Protecting all internal connections on the firewall with a network sensor is the best practice. Sensor 2, connected on the outside network, sees all traffic targeted for the organization, including the traffic that is blocked by the firewall and all traffic leaving the organization's network. This sensor also monitors the DMZ traffic and inside traffic. Knowing what traffic is denied or permitted by the firewall, the network administrator must find out what reported intrusions reported by Sensor 2 are a danger for the network. This sensor also needs to protect the firewall itself against DoS attacks and tools generating noise on the network. Sensor 3 enables you to see which users are attempting to gain access to the protected network (DMZ). All three sensors provide visibility into which vulnerabilities are being exploited to attack servers, hosts, and so on.

Once you have decided which critical assets require network monitoring, the sensors can be connected, starting with the data capturing (sniffing) interface. It may sound ridiculous, but if the sensor cannot see the interested traffic, it does not function properly. It is straightforward to connect the sensor to a network segment by plugging the interface into an open port on a hub, but this becomes an issue in switched environments, where traffic is only aggregated on the backplanes of the devices. In these environments, you can solve the problem by using integrated switch sensors with traffic-capture functions. The SPAN feature or VACL feature can monitor traffic.

NOTE

More information on how to configure your switches for these features can be found at the following URLs: Cisco Catalyst 3550 series switches:

http://www.cisco.com/en/US/products/hw/switches/ps646/products configuration guide chapter09186a008011594e.html Cisco Catalyst 4000 series switches:

http://www.cisco.com/en/US/products/hw/switches/ps663/products configuration guide chapter09186a008012236b.html Cisco Catalyst 6500 series switches:

http://www.cisco.com/en/US/products/hw/switches/ps708/products configuration guide chapter09186a008007f323.html

After connecting the network sensor interfaces, the sensor can be configured either locally via a console or remotely using a network management station.

Before starting to tune the sensor, which is the most important part of the network IDS deployment, it is recommended to use the sensor with the initial sensor configuration and analyze the alarms generated the first couple days. Analyzing the different alarms and tuning out the false positives produces a high-performing security system. Also keep in mind that not every sensor needs to trigger an alarm on every event. Here again, the importance of clearly defined network security policies is obvious. It is also clear that tuning the sensors is an iterative process. Traffic patterns can and do change over time, and sensor tuning is a must.

Once the initial tuning phase is finished, the network administrator can selectively implement response actions. Small organizations that are willing to investigate the deployment of IDSs can start deploying Cisco IOSbased IDSs on a router or PIX-based IDS, instead of buying standalone sensors. The following section presents a brief overview of router IDS and PIX IDS.

Continue reading here: IP Session Logging

Was this article helpful?

+1 0

Readers' Questions

  • Tom
    How sensor placemnt in ids?
    1 year ago
  • Sensor placement in an Intrusion Detection System (IDS) is a critical component of any security system, as it determines the effectiveness of the system in detecting malicious activity. When designing a system, it is important to consider the factors that influence sensor placement, such as the physical layout of the environment, the type of attacks it is designed to detect, and the type of sensors used. Generally, IDS sensors should be placed in areas of high network traffic and in locations where malicious traffic is likely to originate. Additionally, it is important to place sensors in areas where there is no chance of false positives, as too many false positives can lead to costly system repairs.