Intrusion Prevention Systems

Measuring the resiliency–performance, security and stability–of your intrusion prevention system (IPS)

An intrusion prevention system (IPS) is designed to detect malicious activities and drop or sanitize the packets while allowing legitimate traffic to access the corporate network. Validating IPS performance and security for real-world deployment, it is critical to assess the device under the same real-world situations including known vulnerabilities, attack scenarios, custom strikes and legitimate application traffic.

 

IPS performance and security critical to any organization

Because the network environment, both internally and externally, is changing so rapidly an IPS requires constant assessment in order to verify that the device is working properly. Every new software upgrade and/or signature set completely changes the way an IPS performs in a network. In all cases, the data derived from any assessment must be objective, qualitative, and consistent.

The SANS report, “The Top Cyber Security Risks (September, 2009)”, states, “Throughout the developed world, governments, defense industries, and companies in finance, power, and telecommunications are increasingly targeted by overlapping surges of cyber attacks from criminals and nation-states seeking economic or military advantage.” In fact, the threats have become so complex and numerous that organizations often are having difficulty figuring out which threats are the most dangerous.

If an IPS fails to work properly, even letting a single flow of malicious traffic pass can allow viruses, worms and backdoor attacks to gain access to the corporate network and cause a great deal of problems, potentially bringing down the network. Only through proper and realistic cyber simulation can you ensure the performance and resiliency of an IPS and the network.

Measure the resiliency of an IPS with the BreakingPoint Storm CTM™

Effective assessment of IPS performance, security and stability requires an authentic blend of application traffic, combined with live security strikes, at realistic speeds. The BreakingPoint Storm CTM provides users with hundreds of performance and security simulation features, including hundreds of real-world application protocols, thousands of real-time security attacks and millions of users. The BreakingPoint Storm CTM allows enterprises, government organizations, service providers and equipment vendors to put their IPS through the paces of a real-world network and be confident that the device will work when deployed and after any changes are made.