About Us  |  Services  | Recruitment  |  Advertise  | Contact

 

Computer Network Defence Ltd

IDS & IPS Products
Network IPS
Attack Mitigation Systems
Network IDS
Target IDS
Host IPS
Host IDS
Application IDS
Wireless IDS
Honeypots
File Integrity Checkers
Network Taps
IDS Balancers
Switch Port Mirroring
IDS Terms A-H
IDS Terms I-Z
Deploying IDS Guide
Security Info Managers
Scanning Products
VPN & Firewall Products
Forensics Solutions
Content Protection
Training Courses
Raw Packets
Bug Sweeping / TSCM
Miscellaneous
Services


Application
Intrusion Prevention/Detection Systems
A host IDS/IPS would normally concentrate on protecting the hosts Operating System, as the name suggests an application IDS/IPS will work solely with the application itself.  They tend to be tailored to a specific product, such as, Microsoft Internet Information Server (IIS) within application groups that provide externally visible services such as Webservers, Databases and Mailservers. An IDS will report when nefarious activity is detected most usually using logs generated by the application, whilst an Application IPS will not only detect such activity but also block it, protecting the application from attack.



 

Appshield

 

Sanctum, Inc

http://www.watchfire.com/products/appshield/default.aspx

AppShield secures your site by preventing, logging and alerting any type of application manipulation through the browser. AppShield dynamically recognizes the application security policy by analyzing the outbound HTML pages on the fl y. It then enforces compliance with the policy for each incoming HTTP request. The result is solid protection of the application’s integrity, making it nearly impossible for hackers to take advantage of security loopholes. The secure proxy architecture delivers the additional benefits of hiding the network details from users and simplifying the manageability and configuration of the Web application layer.
 

COMMERCIAL

Information Updated: 10 Jun 2002


McAfee® Entercept® Web Server Edition

IIS, Apache, iPlanet

McAfee

http://www.mcafeesecurity.com/us/products
/mcafee/host_ips/web_server_edition.htm

McAfee® Entercept® Web Server Edition prevents unauthorized access to Web servers, the network platforms most easily accessible and frequently used to launch attacks on other network resources. Blending Entercept Standard Edition features with unique Web-server security techniques, Entercept Web Server Edition provides unparalleled protection against the growing battery of known and unknown threats. The result is reduced downtime plus the prevention of server compromise and Web-page defacement.

COMMERCIAL

Information Updated: 30 Nov 2004


McAfee® Entercept® Database Edition

MS SQL

McAfee

http://www.mcafeesecurity.com/us/products/
mcafee/host_ips/database_edition.htm

McAfee® Entercept® Database Edition proactively protects database servers—the heart of the enterprise data center—from new as well as known threats, including the widespread phenomenon of SQL injection attacks. Proven and easy-to-deploy, McAfee Entercept is the only intrusion prevention solution (IPS) with application-specific content interception engines and rules that protect applications, operating systems, and data from attack and compromise.

COMMERCIAL

Information Updated: 30 Nov 2004


SecureIIS™ Web Server Protection

Windows 2000

eEye

http://www.eeye.com/html/Products/SecureIIS/index.html

Intrusion Prevention for Microsoft Web Servers
SecureIIS™ was developed to addresses the security weaknesses of the Microsoft Internet Information Services (IIS) web server application. With the proliferation of web-based applications, web servers have become portals into internal networks, which translate into a requirement of application-level protection, beyond what traditional network firewalls can provide.

By preventing intrusion before and between the time vulnerabilities are detected and accurate patches are issued by Microsoft, SecureIIS obviates this gap of exposure.
Unlike network firewalls that are unable to guard against web server vulnerabilities, SecureIIS integrates within the Microsoft web server application to inspect all traffic before it is processed. This allows SecureIIS to protects against both known and unknown attack types.

This is basically one of the earliest IPS developed.
It technically works as an ISAPI filter which handles te request directed to the IIS and drops it if dangerous, effectively stopping known or possible attacks for which a patch might or might not be installed on the protected machine.

COMMERCIAL

Information Updated: 5 Jan 2004


Computer Network Defence Ltd
Information Security Consultancy and Recruiting
enquiries@securitywizardry.com 

Copyright © 2004 Computer Network Defence Ltd. All Rights Reserved.

PO Box 2680, Corsham, Wiltshire, SN13 0ZR, UK
Phone       0870 3219014
International +44 (0) 1225 811806