Internet.com
ISP-Planet Home
ISP-Planet Survey: Managed Security Service Providers
(Back to Article)

Intrusion Detection / Intrusion Prevention Systems Chart
Provider
IDS/IPS
Platform(s)
Traffic Inspection
Intrusion Detection
Analysis & Response
Response Methods
Additional Comments

Altoria
Intrusion Detection

 

CPE-based

Cisco, ISS

Out-of-Band
In-Line
NW Sensors
Wi-Fi Sensors

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content. 

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Provider analyzes & manually responds to alerts.

NOC monitors events 24/7, investigates alarms to pinpoint issue, contacts customer to recommend actions.

Manual
In-line discard,
TCP reset.

Automated
IP quarantine,
Wi-Fi deauth.

Multiple configurations of Network Sensors & Server Sensors reporting to Central Consoles.

Enhanced Sensor configuration provides customizable auto response & intervention.

Real-time access to security incident reports, detailed event data, auto response reports, & incident trend reports.

AT&T
Internet Protect with Distributed Denial of Service (DDoS) Defense

NW-based

AT&T Proprietary Platform

Out-of-Band
In-Line

[No further details supplied]

Detects Anomalies, Floods, Unusual Behavior.

Provider analyzes & responds manually or automatically.

Customer alerted via page, phone, email; details via portal. Customer can opt to auto-mitigate DDoS or consult first.

Automated mitigation of DDoS attacks.

DDoS attacks are identified & addressed in provider's network—no CPE required.

Automated notification of Internet threats & vendor vulnerabilities.

Portal provides threat description & suggested protection/mitigation strategies.

DDoS attacks are diverted in provider's network; only valid traffic is forwarded to customer.

AT&T
Intrusion Detection

CPE-based

[No platforms enumerated]

Out-of-Band

[No further details supplied]

Detects Signatures, Unusual Behavior.

Provider monitors, analyzes, responds manually.

Customer chooses passive notification or active threat mgt. Tuning period used to establish patterns & correlation to eliminate false positives.

Manual & Automated
IP quarantine.

CPE hosted by customer or MSSP.

Main service is notification of actionable items. Can be configured to auto-shun IP addresses outside the security policy.

AT&T
Intrusion Prevention

CPE-based

[No platforms enumerated]

Out-of-Band

[No further details supplied]

Detects Unusual Behavior

Provider responds manually or automatically.

Can reset, block, or quarantine intruders.

Manual & Automated
IP quarantine,
TCP reset.

Honeynet used to lure & identify intruders by source IP, then reset, block, or quarantine those addresses.

Provider
IDS/IPS
Platform(s)
Traffic Inspection
Intrusion Detection
Analysis & Response
Response Methods
Additional Comments

FiberLink
Managed Threat Protection

Host-based

Fiberlink Extend360

In-line

Inspects:
TCP/IP Hdrs.

Detects Signatures, Unusual Behavior.

Provider monitors & notifies customer.

Host intrusion activity reported via portal, including personal firewall attacks.

Automated
IP quarantine.

Service requires customer to install Extend360 software on each end user's device.

Central intrusion monitoring is provided via web portal.

Personal firewall is automatically restarted in the event of unwanted shutdown.

Getronics
Managed NIDPS

 

CPE-based

Snort, Cisco, McAfee, Enterasys, ISS, AirDefense

Out-of-Band
In-Line
NW Sensors
Wi-Fi Sensors

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Provider monitors, analyzes, responds manually or automatically.

Certainty & severity determines auto-action. Highly volatile incidents researched & handled per SLA - in many cases, to contain/halt attack.

Manual & Automated
In-line discard,
IP quarantine,
TCP reset,
Wi-Fi deauth,
Honeypot.

Works in multi-sourcing environments where 3rd party is responsible for endpoints.

Customer may designate on-site response agent. Nature of attack & monitoring product determines incident response strategy.

Customers are encouraged to conduct a full analysis & design an incident response plan; MSSP consulting services available.

IBM ISS
Managed Protection

CPE-based

ISS Proventia, ISS RealSecure Network

Out-of-Band
In-Line

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior, Vulnerabilities.

Alerts analyzed by AI & reviewed by SOC. If warranted, sends customer email w/ suggested actions.

Select & Premium Service Levels also receive 24/7 human analysis with priority-based escalation. Auto-response when using IPS or firewall.

Manual & Automated
In-line discard,
IP quarantine,
TCP reset.

Leverages each IPS platform to max, taking reliability into consideration.

CPE hosted by customer or MSSP. Includes monthly vulnerability scan.

MSSP uses own IPS platform & Guarantees that network segments, critical servers, & desktops are protected from 800+ attacks on X-Force list. In the event of compromise, MSSP will refund mo. fee or issue cash payment.

IBM ISS
Managed Intrusion Detection and Prevention

 

CPE-based

ISS Proventia, ISS RealSecure Network, Cisco, Juniper, TippingPoint, McAfee

Same as above.

Same as above.

Same as above.

Same as above.

CPE hosted by customer or MSSP. Includes monthly vulnerability scan.

Uses MSSP & industry leading platforms to provide features similar to "Managed Protection" but w/o Guarantee or aggressive SLAs.

MegaPath
SecureConnect Intrusion Prevention

Hosted CPE or NW-based

Fortinet

In-Line

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Service responds automatically.

Events inspected for criticality, direction, & severity. If threshold met, ticket initiates customer email & MSSP review. Ticket escalated if not resolved after 4 hrs.

Manual
IP quarantine.

Automated
In-line discard,
TCP reset.

When attack is detected & signature exists to block attack, access control lists are created to prevent spread until signature can be put in place on delivery platform. 72 hr SLA on signature update for new attacks.

Provider
IDS/IPS
Platform(s)
Traffic Inspection
Intrusion Detection
Analysis & Response
Response Methods
Additional Comments

Perimeter
IDS/IPS

CPE-based or NW-based

Fortinet, Checkpoint, SonicWALL

Out-of-Band
In-Line
NW Sensors

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Customer or Provider monitors, analyzes, responds.

All Alerts & Logs supplied via portal.

Automated
In-line discard,
IP quarantine.

CPE hosted by customer or MSSP. Customer can choose to monitor portal & take own action, have MSSP proactively perform actions, or have MSSP review suggested actions before they are taken.

Secure Designs
Firelan Managed IPS

 

CPE-based

SonicWALL

In-Line plus Wi-Fi Sensors

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

 

Service responds automatically.

Alerts reviewed by SOC based on category. Depending on level, SOC works to isolate & remedy.

Automated
In-line discard,
IP quarantine,
TCP reset,
Wi-Fi deauth.

Must be purchased with firewall. Auto-responses sent as alerts to MSSP support staff for review & take further action as needed.

If notification is required, support staff work with Customer's technical personnel to isolate & resolve.

SecureWorks
Managed Network Intrusion Prevention

 

CPE-based

iSensor, Cisco, Snort, Juniper, ISS

Out-of-Band
In-Line

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Service responds automatically.

For IPS, platform blocks malicious traffic. After correlating alerts, analyst may call customer to discuss or take action. For urgent events, new measures deployed immediately.

Automated
In-line discard,
IP quarantine,
TCP reset.

3 service tiers:
Fully managed
Monitored only
Reporting only

Based on NSS-Certified iSensor.

Extensive automation ensures that analysts are only used when human intervention is desirable & that clients are notified automatically, but only when event warrants. In rare case of compromise, defined escalation matrix is immediately executed while contact is initiated & potential damage is contained.

Solutionary
ActiveGuard Monitored and Managed IDS/IPS

 

CPE-based

Snort, Juniper, Cisco, ISS, TippingPoint, Sourcefire, McAfee, Symantec, AirDefense, AirMagnet

Out-of-Band
In-Line
NW Sensors
Wi-Fi Sensors

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Analysis uses custom rules, time thresholds, & volume anomalies correlated w/ other device info.

Provider analyzes & responds manually.

Security events & IPS device actions are escalated to SOC staff for review, possible customer notification, & countermeasure implementation.

Manual & Automated
In-line discard,
IP quarantine,
TCP reset,
Wi-Fi deauth,
Other.

Actions that can be taken in response to intrusions depend on customer configuration of customer environment. Strategies include firewall or IPS rule implementation to block suspicious traffic, changes to customer environment to remove vulnerabilities, or IDS/IPS tuning.

Provider
IDS/IPS
Platform(s)
Traffic Inspection
Intrusion Detection
Analysis & Response
Response Methods
Additional Comments

Symantec
Intrusion Protection Solutions

 

CPE-based

Juniper, Cisco, ISS, McAfee, TippingPoint, Sourcefire, Enterasys, Snort

Out-of-Band
In-Line
NW Sensors

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Customer or Provider monitors, analyzes, responds.

MSSP takes action or notifies customer based on customer's procedures, in accordance with incident ID & escalation SLAs.

Manual and/or Automated In-line discard, IP quarantine, TCP reset.

Managed IPS service is an add-on to Security Monitoring services that provide real-time monitoring, analysis & incident escalation based on security log data from a wide variety of sources.

IPS devices can be configured in variety of protection modes, including customized in-line blocking with SLA guarantees.

Unisys
Managed IDP

 

CPE-based

Cisco, Fortinet, ISS, McAfee, Sourcefire

Out-of-Band

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Provider analyzes & manually responds.

Central mgmt platform events are integrated via ArcSight ESM, & correlated against other system events. High risk threats are reviewed by analyst. If needed, customer is notified & given recommendations.

Manual Wi-Fi deauth.

Automated In-line discard, IP quarantine, TCP reset.

IPS blocks well-defined attacks. For ambiguous attacks, ESM continues analysis.

CPE hosted by customer or MSSP. Significant analysis is conducted by ESM to correlate events & reduce false positives. If warranted, analyst instructs customer on remediation actions or changes managed device controls.

MSSP highly recommends customer also purchase managed vulnerability scanning service to reduce spurious events & augment IDS/IPS correlation effectiveness.

Verizon Business
Managed Intrusion Detection

 

CPE-based

Cisco, Enterasys, ISS, NAI, Juniper, TippingPoint

Out-of-Band
In-Line

Inspects:
TCP/IP Hdrs,
App Hdrs.

Detects Anomalies, Floods, Signatures, Unusual Behavior.

Provider analyzes & manually responds.

SOC analyzes & prioritizes events, based on customers' traffic, other devices, general population. Customers notified via portal.

Automated In-line discard, IP quarantine, TCP reset.

Response strategy is customer specific, based on customer's security policy, corporate policy, & capability of IDS/IPS platform.

For critical/emergency events, action is reviewed with by phone & performed by customer or SOC.

Verizon Business
Managed Intrusion Protection

Same as above.

Same as above.

Same as above.

Same as above.

Same as above.

Offers proactive protection by utilizing an intrusion prevention device configured specifically to a customer's business needs.

Virtela
Managed IPS

CPE-based, NW-based

TippingPoint, Juniper, Cisco

Out-of-Band
In-Line

Inspects:
TCP/IP Hdrs,
App Hdrs,
App Content,
depending on selected platform.

Detects Anomalies, Floods, Signatures, Unusual Behavior, using most features available within supported platforms.

Customer or Provider monitors, analyzes, responds.

SIM reviews IPS & other device alerts, reflecting customer policies, IPS config, & best practices. High severity alerts follow escalation procedure to deliver summary & recommended action via selected contact method.

Manual & Automated In-line discard, IP quarantine, TCP reset.

Customer may choose to apply recommended action or work with MSSP to determine alternate solution.

CPE hosted by customer or MSSP. Significant tuning required for appropriate IPS rule application. By default, well-qualified events are blocked; manual response used for more subtle events.

MSSP recommends all events that can comfortably use auto-response be deployed in that mode. Customers may choose monitoring only or fully managed service—this choice determines who configures & administers IPS rules.

Provider
IDS/IPS
Platform(s)
Traffic Inspection
Intrusion Detection
Analysis & Response
Response Methods
Additional Comments
IDS/IPS Table Notes
 
  • Services are stand-alone offerings except where noted.
  • CPE = Customer Premises Equipment
  • NW = Network
  • SLA = Service Level Agreement
  • SOC = Security Operations Center
  • IPS = Intrusion Protection Service
  • IDS = Intrusion Detection Service
  • DoS = Denial of Service
  • DDoS = Distributed DoS
  • TCP = Transmission Control Protocol
  • IP = Internet Protocol

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers