<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type='text/xsl' href='http://windowsmvp.spaces.live.com/mmm2008-05-17_13.22/rsspretty.aspx?rssquery=en-US;http%3a%2f%2fwindowsmvp.spaces.live.com%2fcategory%2fSecurity%2ffeed.rss' version='1.0'?><rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:msn="http://schemas.microsoft.com/msn/spaces/2005/rss" xmlns:live="http://schemas.microsoft.com/live/spaces/2006/rss" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Dennis Chung - Windows MVP: Security</title><description /><link>http://windowsmvp.spaces.live.com/?_c11_BlogPart_BlogPart=blogview&amp;_c=BlogPart&amp;partqs=catSecurity</link><language>en-US</language><pubDate>Thu, 24 Jul 2008 03:11:26 GMT</pubDate><lastBuildDate>Thu, 24 Jul 2008 03:11:26 GMT</lastBuildDate><generator>Microsoft Spaces v1.1</generator><docs>http://www.rssboard.org/rss-specification</docs><ttl>60</ttl><cf:parentRSS>http://windowsmvp.spaces.live.com/blog/feed.rss</cf:parentRSS><live:type>blogcategory</live:type><live:identity><live:id>-9216240295232456561</live:id><live:alias>windowsmvp</live:alias></live:identity><cf:listinfo><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="typelabel" label="Type" /><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="tag" label="Tag" /><cf:group element="category" label="Category" /><cf:sort element="pubDate" label="Date" data-type="date" default="true" /><cf:sort element="title" label="Title" data-type="string" /><cf:sort ns="http://purl.org/rss/1.0/modules/slash/" element="comments" label="Comments" data-type="number" /></cf:listinfo><item><title>IPSec makes IPS/NIDS redundant?</title><link>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!547.entry</link><description>&lt;p&gt;I was in a recent discussion with a customer to talk about &lt;a href="http://www.microsoft.com/nap"&gt;Network Access Protection&lt;/a&gt;. Along the lines of discussions (after understanding what NAP has to offer and after an introduction to &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server Domain Isolation model&lt;/a&gt; with IPSec), i was asked this question about Intrusion Prevention Systems (IPS) and Network Intrusion Detection Systems (NIDS). &lt;blockquote&gt; &lt;p&gt;&lt;strong&gt;Does IPSec make IPS/NDS redundant?&lt;/strong&gt;&lt;/blockquote&gt; &lt;p&gt;I will not go into what IPSec does, since it has been available for a rather long period. IPSec existed since Windows 2000 days. Many people think that its only use is for Point-to-Point as in, for a VPN encryption technique. Well, that is right, but IPSec isn't just limited to that. It can do a lot more. &lt;p&gt;It can be used to authenticate machines in the domain, and encrypting anything, on any port, from any source, to any destination, that the administrator wants. Anyway, i shan't teach you what IPSec does because there is a very good resource about it. Visit &lt;a href="http://www.microsoft.com/ipsec"&gt;http://www.microsoft.com/ipsec&lt;/a&gt; to learn about IPSec. &lt;p&gt;Back to the topic here; Does IPSec make IPS/NIDS redundant? &lt;p&gt;As i am not a subject matter expert, i took it back to the Product Team, looking for an authoritative answer. William Dixon, technical co-author of &lt;a href="http://www.microsoft.com/technet/security/guidance/architectureanddesign/ipsec/default.mspx"&gt;Server and Domain Isolation Guide&lt;/a&gt;, responded. He recommended to read up Chapter 1 to 3 of the linked guide. &lt;p&gt;&lt;strong&gt;Definitions of IDS&lt;/strong&gt; &lt;blockquote&gt; &lt;p&gt;Here's the definition of IDS - &lt;a title="http://www.tech-faq.com/ids-intrusion-detection-system.shtml" href="http://www.tech-faq.com/ids-intrusion-detection-system.shtml"&gt;http://www.tech-faq.com/ids-intrusion-detection-system.shtml&lt;/a&gt; &lt;p&gt;In its definition, it says IDS is commonly divided into NIDS and HIDS. The earlier being Network and the latter being Host. &lt;p&gt;New generations of NIDS has the capabilities of doing NIPS. In contrast, one earlier detects, latter prevents. In either situations, they all need the ability to pick up TCP traffic.&lt;/blockquote&gt; &lt;p&gt;&lt;strong&gt;What essentially does IDS need to do its job?&lt;/strong&gt; &lt;blockquote&gt; &lt;p&gt;They all essentially monitors TCP traffic and then take necessary actions accordingly. So, what IDS needs is the ability to monitor TCP packets where its being placed. Here's where the value of the question is being posted. &lt;p&gt;Since IPSec has the capability to scramble a TCP packet (in ESP), won't that prevents IDS/NIDS/NIPS (I'll called them IDS collectively from now, excluding HIDS), from being able to decipher the TCP packets? &lt;p&gt;Essentially yes. If traffic is scrambled, IDS will have trouble deciphering the TCP Packets to monitor, however, that does not make IDS redundant on the network. It depends on the situation, and it warrants a requirements study of the situation. You can email me for a discussion. ;-)&lt;/blockquote&gt; &lt;p&gt;&lt;strong&gt;IPSec can scramble TCP Packets&lt;/strong&gt; &lt;blockquote&gt; &lt;p&gt;IPSec, ESP, has the ability to scramble the TCP packets holding data and make them unreadable to anyone, other than the intended party. Which essentially, IDS is the anyone. However, in Authentication mode, IDS still can play a part in doing what it is supposed to do, thereby, making it not redundant. But if encryption is deployed, IDS cannot monitor such traffic&lt;/blockquote&gt; &lt;p&gt;&lt;strong&gt;The other equations&lt;/strong&gt; &lt;blockquote&gt; &lt;p&gt;In finding the answer of whether IDS is redundant with the use of IPSec. The easy answer is No (May not apply in all situations, most diplomatic is &amp;quot;Depends&amp;quot; LOL). Well, where IPSec is used in ESP mode, IDS won't be able to do its job. &lt;p&gt;In most situations, IPSec encryption is not used on all network traffic. You won't be &amp;quot;IPSec-ing&amp;quot; everything. You will only use IPSec where needed. You can choose the type of traffic to apply IPSec. It can be defined between hosts (eg, between certain server and client) and type of traffic (eg. HTTP, but not ICMP). A combination is also possible. &lt;p&gt;So in fact, if you have machines not joined to the domain, and machines or traffic where IPSec isn't used, IDS still plays an important part of ensuring the network is safe. &lt;p&gt;After applying IPSec to protect your critical assets and data on the network, does the protection of IDS still offer a good compelling value? If yes, you will still want to use IDS. However, if after applying IPSec and you think IDS is not playing an important role in your quest for network security anymore, then i guess no, since you will probably be protecting your critical assets with IPSec encryption.&lt;/blockquote&gt; &lt;p&gt;Give it some thoughts because there are certain cases where IDS does play a crucial role and they can complement IPSec. Remember, the crucial objective is to make sure network is secure and hosts on it are protected, and not what was used. &lt;p&gt;Personally, the choice of the platform/technology to use, is certainly the one (in personal opinion), the one that offers the easiest form of management/deployment and provides the best form of protection for your objectives. &lt;p&gt;There are some more information which i think i will either post later on, or wait for someone to ping me for more information. (Psst, the fact is, i am sleepy and i got to work tomorrow.. Yawn..) Till then again... see ya around. &lt;p&gt;Oh, do check out this web site about Server and Domain Isolation model using IPSec. Essentially, you can make domain assets ignore non-domain machines totally. &lt;a href="http://www.microsoft.com/sdisolation"&gt;http://www.microsoft.com/sdisolation&lt;/a&gt; &lt;p&gt;Happy New Year &lt;p&gt;/Dennis&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-9216240295232456561&amp;page=RSS%3a+IPSec+makes+IPS%2fNIDS+redundant%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=windowsmvp.spaces.live.com&amp;amp;GT1=windowsmvp"&gt;</description><comments>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!547.entry#comment</comments><guid isPermaLink="true">http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!547.entry</guid><pubDate>Tue, 01 Jan 2008 14:51:39 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://windowsmvp.spaces.live.com/blog/cns!80195647FE07388F!547/comments/feed.rss</wfw:commentRss><wfw:comment>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!547.entry#comment</wfw:comment><dcterms:modified>2008-01-01T14:51:39Z</dcterms:modified></item><item><title>... is Windows more secure?</title><link>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!536.entry</link><description>&lt;p&gt;Having been managing Windows infrastructure for many years, the darkest years of Windows are probably over. Recalling Blaster virus in 2002/2003 (can't exactly remember which year), bringing Windows systems down in 60 seconds was horrific for the Windows administrator. That has since been history. &lt;p&gt;Over the years, Microsoft had taken numerous steps, and one of those that i recalled was a stop to all developments in the pipeline. All developers in Microsoft had to go through training on writing secure code. &lt;p&gt;Security has since been a word everyone in Microsoft remembers and had to live with everyday. I guess that is bearing fruit for now. In all product designs, Microsoft has placed Security in top priority. &lt;p&gt;I came across a recent report, from ZDNet, as saying &amp;quot;Apple Mac operating systems had more critical vulnerabilities reported in 2007 than Microsoft's operating systems, according to research.&amp;quot; &lt;p&gt;A figure in the report was interesting. Mac OS X has 234 highly critical vulnerabilities reported in 2007, as compared to just 23 for Vista and XP combined. You can read the report here. &lt;a title="http://news.zdnet.co.uk/security/0,1000000189,39291625,00.htm" href="http://news.zdnet.co.uk/security/0,1000000189,39291625,00.htm"&gt;http://news.zdnet.co.uk/security/0,1000000189,39291625,00.htm&lt;/a&gt; &lt;p&gt;So is Windows more secure than before? I would say yes for sure. However, being in IT, we need to be constantly be reminded that there are no such thing as 100% secure. Security in IT is not just about technology. IMHO, it combines technology, processes, policies and constant updates for the IT Pros. &lt;p&gt;/Dennis&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-9216240295232456561&amp;page=RSS%3a+...+is+Windows+more+secure%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=windowsmvp.spaces.live.com&amp;amp;GT1=windowsmvp"&gt;</description><comments>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!536.entry#comment</comments><guid isPermaLink="true">http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!536.entry</guid><pubDate>Thu, 20 Dec 2007 08:19:27 GMT</pubDate><slash:comments>2</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://windowsmvp.spaces.live.com/blog/cns!80195647FE07388F!536/comments/feed.rss</wfw:commentRss><wfw:comment>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!536.entry#comment</wfw:comment><dcterms:modified>2007-12-20T08:19:27Z</dcterms:modified></item><item><title>Microsoft Security Intelligence Report (Jan - Jun 07)</title><link>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!523.entry</link><description>&lt;p&gt;Microsoft has released a report. &lt;p&gt;It is based on the data derived from several hundred million Windows Users and some of the buiest online services on the Internet. &lt;p&gt;It provides in-depth perspective on trends in software vulnerability. &lt;p&gt;If you're into Security focused role in your organization, this is one of the best source of information that you should read. It is also available in other languages. &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=4EDE2572-1D39-46EA-94C6-4851750A2CB0&amp;amp;displaylang=en"&gt;Grab the report here.&lt;/a&gt; &lt;p&gt;/Dennis     &lt;div&gt;&lt;a href="http://www.statcounter.com" target="_blank"&gt;&lt;img alt="StatCounter - Free Web Tracker and Counter" src="http://c28.statcounter.com/t.php?sc_project=2743791&amp;amp;resolution=1024&amp;amp;camefrom=&amp;amp;u=file:///C:/Users/i-dchung/AppData/Local/Temp/WindowsLiveWriter1286139640/E4C27A74A9D4/index.htm&amp;amp;t=&amp;amp;java=1&amp;amp;security=3da6c25f&amp;amp;sc_random=0.17502684918458705" border=0&gt;&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-9216240295232456561&amp;page=RSS%3a+Microsoft+Security+Intelligence+Report+(Jan+-+Jun+07)&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=windowsmvp.spaces.live.com&amp;amp;GT1=windowsmvp"&gt;</description><comments>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!523.entry#comment</comments><guid isPermaLink="true">http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!523.entry</guid><pubDate>Fri, 07 Dec 2007 04:05:28 GMT</pubDate><slash:comments>2</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://windowsmvp.spaces.live.com/blog/cns!80195647FE07388F!523/comments/feed.rss</wfw:commentRss><wfw:comment>http://windowsmvp.spaces.live.com/Blog/cns!80195647FE07388F!523.entry#comment</wfw:comment><dcterms:modified>2007-12-07T04:05:28Z</dcterms:modified></item></channel></rss>