3 ms·
This isn't true. One of the things I'm famous for is creating "BlackICE" 15 years ago, an intrusion-detection technology that we shipped as a variety of produc
by robertgraham 12y ago
This isn't true.
One of the things I'm famous for is creating "BlackICE" 15 years ago, an intrusion-detection technology that we shipped as a variety of products, such as a personal firewall, gigabit IDS, and inline protection (i.e. intrusion-prevention-system or IPS).
The distinguishing feature of this technology is that we wrote "protocol-decodes" for everything. This made the product faster, able to catch more things, yet producing fewer false-positives. It's a vastly better technique than Snort-style pattern-matching.
Yet, it was an uphill battle convincing the market of this. That's because people are stupid and don't understand how things work well enough to appreciate the difference. All they know is that they download a public exploit, run it, and if the IDS catches it, then the IDS is good.
Today, there are lots of commercial products that do things the right way, with protocol decodes. There is also the open-source "Bro" project which does things the right way. All these products can catch my heartleech tool -- it can't evade tools doing things the right way.
Even Snort often does things the right way, but only when people like me prod them. They are going to add an SSL decode (I predict).
So the upshot is this: I really are about the difference between protocol-analysis and pattern-matching in IDS technology, and as long as people like you aren't smart enough to understand the difference, I'm going to keep releasing exploits to demonstrate it. None of my exploits evade properly written IDS -- only IDS that takes shortcuts.
- tptacek 12y agoI don't think I had a problem with "heartleech" until I read this comment. What exactly does Snort's TLS decoding have to do with extracting private keys from servers? That's not the bug. The bug is OpenSSL leaking memory when it receives a malformed TLS heartbeat. You could have demonstrated that without publishing "find_private_key()". I think you published this because it was fun to write. "Auto pwn", as you call it, has nothing to do with convincing Snort to do anything. I don't believe you agree with Daniel Weber's argument at all. Don't dodge it by making things up. Engage with it directly. I wouldn't think it would be that difficult for you to knock down.
- robertgraham 12y agoBecause Snort's signatures can't detect 'heartleech'. But most other IDSs can, such as Bro. Unless there is a tool that demonstrates this, people won't believe that there is a difference between Snort and Bro, because existing tools don't show a difference.
- tptacek 12y agoYou didn't address what I wrote. The demonstration didn't require the extraction of private key material from servers, because that's not the bug. The difference between Bro and Snort has nothing to do with private key material.
- robertgraham 12y agoPeople are good at convincing themselves there is no problem. Vendors are good at convincing people there is no problem. The demonstration has to hit them over the head with the obviousness of the exploit. If the private-key pops up automatically, and a sensor didn't detect it, they have to believe. Otherwise, when the sensor doesn't fire, they'll believe that the exploit is at fault.