© SANS Institute 200
8
,
Author retains full rights.
© SANS Institute 200
8
, Author retains full rights.
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
Network IDS & IPS Deployment Strategies
to place such systems on a backbone network capable of pushing large globs of data
at extremely high transfer rates. To work around this issue, we place the IDS or IPS
between each department level network and the university backbone. Acquiring
systems capable of lower throughput will be more cost effective, and a distributed
monitoring infrastructure will also provide awareness of network activity in each
segment of the greater network. Figure 2 shows such a setup with circuits labeled
with their associated data transmission capabilities. The magnified portion of Figure
2 leads us into the next sections covering detailed explanation of IDS/IPS
deployment.
This section was admittedly a digression from the main topic. However, the
concentric circles and segmentation of the network described here are crucial to
understand and consider when planning the logical placement of an IDS or IPS. The
concepts explained here are referred to in the remaining sections of the document.