Skip Links

Network World

Brad Reese

Intrusion detection systems vs. network behavior analysis: Which do you need?

By Brad Reese on Wed, 09/10/08 - 12:14am.
Newsletter Signup

Welcome to the first in a three-part series on network behavior analysis through the eyes of Plixer International. The second part in the series focused on NetFlow analytics vs. network behavior analysis, while the third focused on network behavior analysis and DoS attacks.

Marc BilodeauMore and more vendors are touting the "security features" of their products with such acronyms as IDS, NBA, IPS, firewalls and a slew of others.

Thoroughly confused, yours truly asked Plixer Cofounder and CTO Marc Bilodeau the following six questions in order to better understand the differences between IDS and NBA systems, as well as a few others:

1. What is an Intrusion Detection System (aka IDS)?

"An intrusion detection system generally sits on the internet connection and snoops on packets. It is used to detect malicious behaviors that try to sneak onto the network and compromise the security and trust of a computer system. This includes network attacks on vulnerable services, data driven attacks on applications, host based attacks such as privilege escalation, unauthorized logins and access to sensitive files, and malware (viruses, trojan horses and worms). Once in, the virus or infection can hang out for weeks before it strikes out on its evil mission."

-----------------------------------

2. Won’t regular signature updates to the IDS help keep the threat database up to date?

"Yes signature updates are helpful, but because crackers are constantly evolving their nasties to get past the latest security shields, the company is never completely immune. I like to compare 'signature updates' to a routine flu shot injected into the human body every year to protect it against the most threatening viruses. However, it never blocks all flu viruses."

-----------------------------------

3. What is Network Behavior Analysis?

"Network behavior analysis is the ability to identify traffic patterns that are not considered normal in the day to day traffic of the network. Simply put, this is the industry's attempt to identify irregularities in the network beyond simple threshold settings for excessive traffic. One of the most watched for network security breaches is an abnormal traffic pattern known as a Distributed Denial of Service attack (DDoS). It is a significant security threat to internet service providers and large network infrastructures."

-----------------------------------

4. What about Intrusion Prevention Systems (aka IPS), how is it different from the IDS or NBA?

"Intrusion prevention systems generally work in conjunction with IDS and NBA systems. When an attack is detected by the IDS or NBA, the IPS can drop the offending packets while still allowing all other traffic to pass. I like to compare IPS technology to taking Tylenol to help my body operate while it fights the symptoms of the flu. This is ideally done at the switch which can also perform NBA."

Bilodeau notes that Cisco and HP support NetFlow and sFlow respectively, but they perform NBA at the switch without sFlow or NetFlow.

-----------------------------------

5. How can a system with Network Behavior Analysis (aka NBA) abilities help a company with both IDS an IPS already in place?

"In my opinion, an NBA system can be considered a bit less proactive than an IDS and generally focuses on internal traffic. It can sit on a connection and snoop packets like an IDS or it can leverage NetFlow. I say less proactive because an NBA tries to recognize problems that are already underway (e.g. Network scans or DDOS attacks that are being carried out). It tries to catch threats missed by the IDS or antivirus software. An NBA appliance addresses anomalies in network traffic that deviate from standard behavior patterns. Because the NBA system focuses on behavior or symptoms, updates to the analysis engine are made less frequently than that of an IDS. In keeping with my flu example, the flu shot (i.e. IDS) didn’t work. You are sick and the body (i.e. NBA) recognizes a stuffy nose, sinus pressure and a host of other ailments."

-----------------------------------

6. So which do you need: IDS or NBA?

"Well, if you have an IDS, and want to know if an NBA should be added, I would answer with: Can the business benefit from the additional security monitoring an NBA provides? Are you worried about internal threats, most companies are?

"I want to add that at Plixer we developed an industry first technology called Flow Analytics which has many NBA capabilities, but it also provides useful enterprise wide information across hundreds of flow sending routers and switches."


It certainly appears that you need both IDS and NBA, do you agree?

Contact Brad Reese
http://www.BradReese.Com

Search 31,427 Cisco Job Openings

Post Cisco Network Engineer Jobs

View 1,595 items of Refurbished Cisco

Examine CCIE Resumes

Consider 697 Cisco Certified
Network Engineer Resumes

  
Brad's Favorite Top 5 Picks
# 1. Cisco Tools
# 2. Cisco vs. Competitor Lab Tests
# 3. Cisco Engineering Support Directory
# 4. Cisco Repair and Hardware Troubleshooting
# 5. Cisco Product Quick Reference Guides, CPQRGs
Brad Reese on Cisco Story Archives Brad Reese on Cisco Story Archives

Cisco Jobs

Cisco Resumes

2008 Cisco Salary Rates

Nine Year Worldwide CCIE Count

  
Welcome, visitor. Register Log in
About Brad Reese on Cisco

Brad Reese cofounded BradReese.Com Cisco Refurbished, which enables affordable networks globally by assuring customer satisfaction with guaranteed one year warranties on both Cisco Repair as well as Refurbished Cisco.

Don't be shy, contact Brad Reese online or call him Toll Free:

866-864-0506

International callers may wish to call Brad by dialing:

850-364-4115

Archives
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
Categories
A classic scam to defraud Cisco's SMARTnet program
America's Best profile written by Useem regarding Chambers' success
Avian Securities Senior Telecom Research Analyst - Catharine Trebnick
Breakingviews.com correspondent - Robert Cyran
CCIE
Careers
Charlie Giancarlo - Managing Director of Silver Lake Partners and Skype investor
Cisco
Cisco ASR 9000 architecture
Cisco ISR G2 Module Support
Cisco Integrated Services Router Generation 2 (ISR G2) Model Comparison
Cisco Integrated Services Routers Generation 2 Portfolio
Cisco Unified Communications Support for Microsoft Windows 7
Cisco is pushing their ASR 9000 at very competitive prices
Cisco is warning Unified Communications customers about NOT successfully offering support for Microsoft Windows 7
Cisco technical star Jonathan Rosenberg
Cisco will have no liability for any delay in delivery
Data Center
Douglas Smith - Cofounder and President of Network Instruments
Expand visibility of NetFlow-dependent NBAD and compliance applications
GigaStor captures and converts packets in NetFlow data flows
Index Venture partner Danny Rimer
Jonathan Rosenberg - a Cisco Fellow in Cisco's Voice Technology Group
Juniper MX960 lab test results
LANs / WANs
Mark Roberts - Polycom vice president of partner marketing
Michael Useem - Professor of Management
Microsoft
NetFlow
NetFlow add-ons
NetFlow overhead can overtax infrastructure
Network Behavior Anomaly Detection (NBAD)
Network Management
Non-NetFlow capable devices are blind to local traffic
Produce NetFlow about any device
SMB
Security
Selection committee member for America's Best Leaders
September 2009 vs. October 2009 Worldwide CCIE Count Comparison
Silver Lake Managing Director - Egon Durban
Skype's cofounders Niklas Zennstrom and Janus Friis
Software
The Charlie angle is to keep Dave Roux on track
The new Cisco ISR G2 portfolio is priced as follows
VoIP / Convergence
What are the benefits of GigaStor NetFlow Agent?
What’s new on the Cisco ISR G2 models vs. the old ISR models?
Windows 7
Windows 7 just not worth an all-out urgent effort by Cisco to support
Wireless / Mobile
eBay CEO - John Donahoe
sFlow
sFlow and NetFlow provides extended visibility
On The Web
Twitter