Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
(ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
08-11-2013, 10:49 AM, (This post was last modified: 08-11-2013, 10:49 AM by shah_acap.)
Post: #1
(ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
apa beza antara WAF & IPS
penerangan secara senang....
TQ
Reply
08-11-2013, 11:26 AM,
Post: #2
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
xjauh beza cuma pendekatan yang sama.. IPS prevent segala mcm2 jenis categori attack.. contoh mcm kategori seperti backdoor.. jenis signature nya jenis generate.. so apa2 jenis signature IPS akan drop connection..

master WAF kena tnya p0pc0rn..
[Image: pumpkids]
Reply
08-11-2013, 11:33 AM,
Post: #3
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
SANS punya artikel ni agak ringkas dan padat untuk paham.

https://www.sans.org/security-resources/...rewall.php

  ▲
▲ ▲
Spoiler:

surah Ali Imran Ayat 31

Reply
08-11-2013, 03:14 PM,
Post: #4
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
tq pumpkids and ak47suk1...link yg diberi byk membantu..
Reply
08-11-2013, 11:34 PM, (This post was last modified: 09-11-2013, 12:49 AM by fatah.)
Post: #5
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
WAF layer 7 inspection & prevention, while NIPS layer 2 inspection & prevention.
̿ ̿ ̿̿'̿̿\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ - انا کڤيتݢولوڠ
http://fatah.afraid.org/
[Image: 763440762.png]
Reply
09-11-2013, 05:56 PM,
Post: #6
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
sedikit lari topic, tp IDS pon boleh act macam IPS rasanya kalau kita set rules byk2 kan? correct me if im wrong please.
we don't belong together
Reply
10-11-2013, 12:06 AM,
Post: #7
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
Nope, jika "NIDS"/detection engine (e.g: Snort/Suricata/etc) boleh prevent/drop matched/bad packet (dari signature database), jadi NIPS.

NIDS - Network Intrusion Detection System
NIPS - Network Intrusion Prevention System

GayFace
̿ ̿ ̿̿'̿̿\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ - انا کڤيتݢولوڠ
http://fatah.afraid.org/
[Image: 763440762.png]
Reply
10-11-2013, 01:50 AM,
Post: #8
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
(10-11-2013, 12:06 AM)fatah Wrote: Nope, jika "NIDS"/detection engine (e.g: Snort/Suricata/etc) boleh prevent/drop matched/bad packet (dari signature database), jadi NIPS.

sorry x paham ayat ni.. boleh tlg explain?
we don't belong together
Reply
10-11-2013, 01:52 AM,
Post: #9
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
NIDS ni detect ja, NIPS ni detect & prevent sekali. Kalau ada attack, NIPS drop/block terus.
̿ ̿ ̿̿'̿̿\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ - انا کڤيتݢولوڠ
http://fatah.afraid.org/
[Image: 763440762.png]
Reply
10-11-2013, 01:57 AM,
Post: #10
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
tp bukan ke kalau IDS detect threat yg match dengan rules tu dye akan block terus?
we don't belong together
Reply
10-11-2013, 01:58 AM,
Post: #11
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
Aku takut kau terkeliru dengan term IDS/NIDS dengan nama produk e.g: Snort. Snort boleh jadi NIDS mode atau NIPS mode, bergantung kepada camna kau configure benda ni.
̿ ̿ ̿̿'̿̿\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ - انا کڤيتݢولوڠ
http://fatah.afraid.org/
[Image: 763440762.png]
Reply
10-11-2013, 09:18 PM,
Post: #12
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
(10-11-2013, 01:57 AM)SKL Wrote: tp bukan ke kalau IDS detect threat yg match dengan rules tu dye akan block terus?

bgantung pd software/appliance/configuration... selalunya IDS based on trigger system..dr pengalaman aku la..
"Tanda ilmu itu berkat ialah semakin tinggi ilmu kita,semakin tunduk rendah kita bertawaduk kepada Allah dan juga sesama manusia.Merasakan betapa hebatnya Allah dan tinggi ilmuNya sehingga kita berasa betapa kerdilnya ilmu kita"
[Image: 2770527825.png]
Reply
06-12-2013, 08:03 AM, (This post was last modified: 06-12-2013, 08:15 AM by lowyatt321.)
Post: #13
RE: (ASK) Web Application Firewall (WAF) vs Intrusion Prevention System (IPS)
WAF -reverse proxy/transparent reverse proxy Layer 7
NIPS-transparent layer 2

Teknik deteksi asas antara:
negative security model-signature/rule/weighted/scoring
Positive security model-whitelist
or
hybrid with their own method-anomaly/statistic/correlation/scoring etc2....
Reply


Possibly Related Threads...
Thread Author Replies Views Last Post
  (ASK) Beza antara Next Generation Firewall (NGFW) vs Unified Threat Management (UTM) shah_acap 6 835 14-11-2013, 01:34 AM
Last Post: RFC792
  [ask]firewall skyz3r 3 475 24-10-2012, 11:19 AM
Last Post: skyz3r

Forum Jump: