IDS, detection of encrypted packets within non-SSL traffic streams?

Unanswered Question
Feb 16th, 2010
User Badges:


Here's the scenario:

There's a host on the internal network that has a reverse shell to the outside world, and the packets being sent back to the attacker are encrypted, over a standard web (TCP/80) port - which is allowed by Websense or URL filter of choice.

Can a custom signature be created to alert on the detection of encrypted packets / data streams over non-encrypted transmissions? We've found other IDS/IPS systems that we're able to build custom sigs to detect and alert on these streams, but are wondering if we can do that in within Cisco IDS/IPS?

Please be specific if possible...let's assume the organization is using the latest version of Cisco IDS software.

Thanks in advance...

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
bnidacoc Wed, 02/17/2010 - 08:40
User Badges:

Have you got Sig 11233 series enabled?  It does, BTW, appear to exclude "WEBPORTS."  Maybe a copy could be made to exclude only TCP 443.


This Discussion