ellen_messmer
Senior Editor, Network World

Three IPS products pass security evaluation tests

News
Jun 26, 20062 mins

Out of 10 submitted for scrutiny.

ICSA Labs‘ first tests evaluating intrusion-prevention systems have yielded just three that made the grade out of 10 submitted for review.

According to the results announced last week, the three IPS products that passed were NetKeeper from BroadWeb, one Proventia model from Internet Security Systems and 3Com’s TippingPoint appliance. Jack Walsh, ICSA Labs program manager, said the rest of the products – which he left unnamed under the lab’s policy but which he indicated were from major vendors – weren’t able to detect 100% of the challenges thrown at them in the lab setting.

Passing the test Of 10 vendors’ products tested in ICSA Labs’ intrusion-prevention system evaluation, only three attained the required performance and accuracy goals:
ProductMaximum average one-way latency
BroadWeb’s NetKeeper 3256P (100Mbps)441 microsec (1,500 allowed)
Internet Security Systems’ Proventia G400 (350Mbps)398 microsec (1,430 allowed)
3Com’s TippingPoint 5000E (3Gbps)84 microsec (398 allowed)

“They had to get all the attacks targeting the IPS,” Walsh says. “They were allowed to correct for initial failure and had three days to fix it.”

ICSA Labs, a division of Cybertrust, has evaluated anti-virus products and firewalls in the past. The IPS tests, which began last November, marked the first time the test lab evaluated such equipment, which is supposed to detect and block attacks and malware. The goal was to evaluate how well the 10 IPSs did when subjected to a battery of probes.

Network World also is testing half a dozen IPS products, with results to be released in late summer.

At ICSA Labs, the IPS equipment had to detect 219 attacks on application and operating system vulnerabilities, plus recognize and defend against SYN floods and other denial-of-service attacks.

The attack traffic was mixed in with thousands of gigabytes of legitimate traffic that ICSA Labs had obtained from Cybertrust business customers that volunteered large traffic streams for this purpose.

“It’s an intelligent replay of the gigabytes of traffic that Cybertrust corporate customers volunteered,” Walsh says. ICSA Labs used a mix of tools, including the Tomahawk open source IPS testing tool, Core Impact’s penetration-test suite and in-house scripts.

During the evaluation, the IPS products didn’t have to be identical in speed, but they did have to meet acceptable latency guidelines.

The three products that made it through the tests gain recognition under the ICSA Labs certification program. Walsh says ICSA Labs will continue doing IPS testing. Another laboratory-based organization that tests IPS products is the U.K.’s NSS Group.