IPSes are Coming of Age

IPSes are Coming of Age

Written By
Dennis Fisher
Dennis Fisher
Feb 7, 2005
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Four years ago, the intrusion prevention system market consisted of a few next-generation intrusion detection system appliances with elementary blocking capabilities. Most vendors and analysts at the time said IPSes would remain a minor offshoot of the IDS segment, mainly because administrators were loath to run appliances that could block network traffic actively.

Those predictions, however, are proving false. The IPS sector has grown steadily and drawn the interest—and the deep pockets—of heavyweights such as Cisco Systems Inc. and 3Com Corp. The IPS market now encompasses a variety of in-line host and network solutions as well as large-scale network monitoring systems capable of making real-time changes in routers, switches and other devices to fend off attacks.

/zimages/1/28571.gifClick hereto read eWEEK Labs review of Top Layer Networks IPS.

Some vendors, such as Sana Security Inc., have even moved the IPS concept to the desktop.

All this activity comes even as many experts say IPSes are still in their infancy, with much room left to mature. A key factor in that maturation will be the convergence of IPS with other security technologies, including IDS and firewalls and perhaps even anti-virus software, experts say.

“The threats are getting faster, and were seeing more polymorphic code. The new appliances youll see down the road will be able to look directly at the behavior of malware and not the signature,” said Steven Hofmyer, founder and chief scientist at Sana, based in San Mateo, Calif. “You will get more systems that use behavioral heuristics. If you can change the game so that you only need signatures about 10 percent of the time, thats a big change.”

Today, most IPSes—like their IDS forebears—rely on signatures to identify attack traffic. A few use a system that models normal traffic on a protected host or network to help identify anomalies. Both approaches have their strengths and weaknesses, but Hofmyer said he believes that in the near future, most enterprise IPS solutions will incorporate a combination of the two.

“I think youll see IDS incorporated into IPS and anomaly detection; signatures and the option of prevention or just detection mode will all be part of it,” Hofmyer said. “Still, not everyone will want to run it in prevention mode 100 percent of the time.”

Other vendors also see convergence on the horizon and say enterprise customers now depend on IPS solutions to such an extent that they are considered part of the network infrastructure, much like switches or firewalls. Thats a far cry from the days when administrators would keep the IPS in listen-only mode for months for fear it might block legitimate traffic.

“Whats really important to customers now is that the products have the same level of maturity as other network security gear,” said John Parker, director of product management at McAfee Inc., based in Santa Clara, Calif. “The IPS cant go down, but addressing redundancy and failover is not trivial. Were looking at redundant management now because what if theres a failure, and the next big outbreak occurs at that point?”

There are other challenges ahead for IPS as well. For example, how will the systems handle emerging technologies such as VOIP (voice over IP), which is becoming a mission-critical enterprise application?

/zimages/1/28571.gifTo help IT managers develop a request for proposal for prospective IPS vendors, eWEEK Labs has put together a series of questions that can serve as a starting point.Click herefor the sample RFP.

“Theres a challenge there in terms of recognizing and decoding packets for VOIP,” said Jason Anderson, product manager at Lancope Inc., based in Atlanta. “Not everybody can do it. IPS is not going to solve all of your problems. Theres an important and necessary position for IPS in the enterprise, but its still only a piece. Its great for eliminating a certain amount of noise, but you still have to cover the traffic that gets through.

“IPS is more broadly accepted for prevention now, but its still typically turned on for a small subset of traffic where it can be highly accurate,” Anderson said.

/zimages/1/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.