Internet Security Systems this week is expected to take the wraps off two intrusion-prevention systems – the Proventia G400 and G2000 – designed to block spyware and hundreds of types of attacks.
With the G2000, which reaches 2G bit/sec, ISS enters the high-speed IPS market to compete against vendors offering multi-gigabit IPS, including McAfee and 3Com’s TippingPoint Technologies division. ISS also is upgrading its entire G line, which starts with the 100M bit/sec G100, to provide gateway-based blocking of roughly 7,000 types of spyware and adware, and a range of improved management features.
First off, ISS is adding the ability to exert policy-based protections based on IP address range or virtual LAN (VLAN ) segment.
“Previously, we only allowed policy by device, regardless of the number of ports,” says product manager Chris Simmons. “It can now be by the device, number of ports and VLANs.”
In addition, ISS is offering an optional Web-based management interface as an alternative to its SiteProtector management system for IPS deployments of up to five supported devices. The Web-based managed interface is far simpler than SiteProtector and will make it easy for smaller firms to deploy IPS, according to ISS.
ISS also is adding SNMP management support so that the G line can be integrated into third-party network management products. The G series ranges in price from $10,000 to $100,000.
All IPSs on the market are prone to issuing false alerts at some point when put into production. The kind of passive intrusion-detection sensors that have been used for years also generate false positives but don’t block traffic. However, an IPS may instantly respond to a false positive by blocking legitimate traffic. This is one reason network managers often use IPS in what’s called “mixed mode,” configuring it to block some types of attacks but not others.
To lower the possibility of false positives blocking good traffic, ISS has added an option to its IPS for a pre-configured security policy it calls the Trust X-Force Prevention Policy.
New from ISS The G400 at 400M bit/sec and the G2000 at 2G bit/sec round out the G line of IPS appliances, which offers: | |||||||||
|
This option is a default setting that ISS crafted to block attacks of a critical nature but allow more wiggle room on false positives. “For smaller companies, this should be an easier way to get started with IPS,” Simmons says.
The ISS appliances also have a “virtual-patching” feature. When a software vendor discloses a new vulnerability and releases a patch, the ISS appliances receive an update that essentially duplicates the patch to block any exploits based on the disclosed vulnerability.
“It’s not as though you don’t need to patch your systems at all, but you’ve bought yourself some time,” says Clarence Morey, ISS senior manager of product strategy.
Some companies say they’re investigating how they might use IPS but are still wary about false positives.
“I’m a little skeptical,” says Jeff Nigriny, chief security officer at Exostar, an e-commerce exchange for the aerospace and defense industry in Herndon, Va.
Nigriny says he still maintains both network- and host-based intrusion-detection systems (IDS), including those from ISS and Enterasys Networks, on Exostar’s corporate network, despite continuing issues associated with false positives. But he says the number of false positives leaves him wary about automating response.
Exostar has branched out into newer types of passive monitors by deploying an IDS from Intrusic called Zephon in proximity to its most critical database servers to determine if an intruder might be stalking the network. Intrusic watches for anomalies that indicate suspicious activity that could mean an attacker has gotten in.




