FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] HIPS experience

To: "'Firewall Wizards Security Mailing List'" <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] HIPS experience
From: "Paul Melson" <pmelson@gmail.com>
Date: Wed, 16 May 2007 15:02:48 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <002001c7965f$dda499c0$321919ac@powerup64>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <eaf24a8a0704121448j8ff10b6oec0e810060779637@mail.gmail.com><fc878bfa1d83.4634f354@tm.net.my> <002001c7965f$dda499c0$321919ac@powerup64>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Thread-index: AceWYitB6XHJlgOUQzOAVF6RAgcmwQBht4UA
> I am looking for feedback from those that have rolled out HIPS (host
intrusion prevention).
> I am looking for both server and desktop based and would be interested in
which vendor was
> chosen and why.  This far I have looked at SANA, Determina, and about to
look at ISS and
> Macafee.  On the destop we are running xp sp2 with NAV, so I am wondering
if I want to use
> hips that supply firewall/av capability.  SANA seems to have alot of bells
and whistles but
> is a/confusing b/takes a while to train (esp on servers)

I've done several HIPS server roll-outs, all Entercept/McAfee.  I was only
involved in one comparo project, and it was Okena Stormwatch (now Cisco)
heads up against Entercept (now McAfee) and there was really no competition.
I've not looked at SANA or Determina beyond their cut sheets.

But here is my advice in rolling out HIPS, especially on servers.

1. Benchmark performance on the servers.  For Windows, using System Monitor
is fine.  Use the following Perf Objects:
Processor / % Processor Time
Memory / Pages/sec
Memory / Available Mbytes
Physical Disk / % Disk Time

Compare performance with and without HIPS.  Note where servers need more
hardware to accomidate HIPS.  Also keep an eye out for performance
conflicts.  HIPS is invasive and can screw things up.  This can be
especially true of vendor A's HIPS product trying to cohabitate with vendor
B's AV product.

2. Plan time for deployment and plan 4x that time for initial tuning.  One
thing Entercept did shortly before McAfee acquired them was to create a kind
of step-up policy configuration.  From deployment you can turn on their
'high' level events and then medium, and low and so on.  And you can do this
in a way that keeps you from being deluged with events from the time you
turn on the agent.  Of course, I think this probably also leads to most
deployments never 'stepping up' to more detailed detection.  Plan to 'step
up' and expect to spend lots of time tuning.  If your HIPS vendor doesn't
have a tiered protection/logging policy like Entercept does, well, make that
6x as much time.

3. When creating policy, logically group and deploy by application and
function, not by OS version.  A Win2K3 server running WebSphere is more like
a Win2K server running Jboss than it is like a Win2K3 domain controller.
Group them together because their policy and tuning should be similar.  (Of
course, a Solaris server running J2EE should not be tuned the same as a
Win2K server running Jboss.)

PaulM


_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>