cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
693
Views
0
Helpful
7
Replies

Proxy Monitoring with IPS / MARS

daniel.litwin
Level 1
Level 1

I would like to monitor proxy bypass connections and report on them. We have MARS and IPS modules in our 2 ASA5520.

1 Accepted Solution

Accepted Solutions

You run the risk of false positives, but have you tried IPS sig ID 5188(and the subsignitures) or creating your own custom signiture. We use some IPS 4200s in my district and have had some false positives, but to date it was non-work related websites.

View solution in original post

7 Replies 7

mhellman
Level 7
Level 7

What do you mean by "proxy bypass connection"? Do you mean attempts by users to bypass an HTTP proxy?

daniel.litwin
Level 1
Level 1

I mean students who use anonymizer programs: surfcontrol, etc. to bypass our internet content filter software. i would think that the IPS could detect some of these and report on it.

It is very difficult to detect such things effectively, even at the proxy. Many of them utilize HTTP CONNECT tunnels that look just like any other HTTPS connection to the Internet. The only thing the typical proxy sees is the "CONNECT :443". The network IDS sees even less...it only sees the SSL handshake and then encrypted data (so it has andst IP address, but that's it). Many URL filters have a category for anonymous proxies, but don't count on them stopping a determined user. They may stop the casual user from using an anonymizing service though. A network IDS/IPS is not going to do this effectively. IMHO, the proxy is the place to do this.

There are gateway(proxy) product that supports SSL inspection(MITM), like WebWasher or BlueCoat. These will be able to see the unencrypted HTTP data and will have a better chance at detection.

http://www.securecomputing.com/index.cfm?skey=1536

Thanks. We are using 8e6 as our web content filter, but I was wondering if MARS or IPS could specifically help with monitoring/blocking proxy/anonymizer attempts. Multiple security layers are always a good thing. So MARS/IPS can't really help with stopping these?

IMHO, MARS/IPS can't do it well enough for it to be worth the effort. I'm not familiar with 8e6, but you might have a look at this:

http://www.8e6.com/anonymous_proxies.html

Thanks. That is what we currently have. I guess I continue to use what we have.

You run the risk of false positives, but have you tried IPS sig ID 5188(and the subsignitures) or creating your own custom signiture. We use some IPS 4200s in my district and have had some false positives, but to date it was non-work related websites.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card