Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 15th, 2009, 07:31 PM
nhamilton nhamilton is offline
Regular Poster
 
Join Date: Jul 2007
Posts: 60
Default Is hips a firewall?

The term hips seems to mean many things to many people, same with the word firewall. So how I describe things people might not totally agree with. This is more just so I can get a better understanding in my own mind.
Some points we will see if we agree on any of them
  • HIPS based software controls what an application is allowed to do and not allowed to do
  • It monitors what each application tries to do and works out if a sequence of behaviour is valid
  • Part of the monitoring is how it use the network/internet
  • To prevent an application doing something you do not wish with the

network, you need be to able to filter and block connections/packets.
If those 4 points are true, then wouldn’t that mean a HIPS security app needs to be a firewall as well? or is my understanding of how people refer to HIPS wrong?
  #2  
Old April 15th, 2009, 08:17 PM
alex_s alex_s is offline
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,072
Default Re: Is hips a firewall?

Quote:
Originally Posted by nhamilton
The term hips seems to mean many things to many people, same with the word firewall. So how I describe things people might not totally agree with. This is more just so I can get a better understanding in my own mind.
Some points we will see if we agree on any of them
  • HIPS based software controls what an application is allowed to do and not allowed to do
  • It monitors what each application tries to do and works out if a sequence of behaviour is valid
  • Part of the monitoring is how it use the network/internet
  • To prevent an application doing something you do not wish with the

network, you need be to able to filter and block connections/packets.
If those 4 points are true, then wouldn’t that mean a HIPS security app needs to be a firewall as well? or is my understanding of how people refer to HIPS wrong?

The names are the most confusing thing .. the problem is we need them to communicate
  #3  
Old April 15th, 2009, 08:46 PM
majoMo's Avatar
majoMo majoMo is offline
Frequent Poster
 
Join Date: Aug 2007
Posts: 309
Default Re: Is hips a firewall?

Quote:
Originally Posted by nhamilton
then wouldn’t that mean a HIPS security app needs to be a firewall as well?
IMO not at all.

You are sure; some confusion there are in conceptions about.

I like to return to the source concept and notion:

HIPS - enhance Anti Virus.

NIPS - strengthen Firewalls.
  #4  
Old April 15th, 2009, 08:56 PM
Mem Mem is offline
Frequent Poster
 
Join Date: Mar 2005
Posts: 275
Default Re: Is hips a firewall?

As ill-intended code needs to modify the system or other software residing on the machine to achieve its evil aims, a truly comprehensive HIPS system will notice some of the resulting changes and prevent the action by default or notify the user for permission.

The role of an IPS in a network is often confused with access control and application-layer firewalls. There are some notable differences in these technologies. While all share similarities, how they approach network or system security is fundamentally different.


http://en.wikipedia.org/wiki/Intrusi...vention_system

or the easy definitions - HIPS controls/notifies about code on the PC that is doing something suspicous internally. You can whitelist applications to not notify in the future. A firewall controls/notifies about packets at the network interface and can be just inbound or inbound/outbound with rules and/or application settings.
  #5  
Old April 15th, 2009, 11:12 PM
TechOutsider's Avatar
TechOutsider TechOutsider is offline
Frequent Poster
 
Join Date: Sep 2008
Posts: 525
Default Re: Is hips a firewall?

Some HIPS may monitor network traffic, similar to a firewall.
  #6  
Old April 16th, 2009, 01:47 AM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 3,743
Default Re: Is hips a firewall?

+++ A "convential firewall" is a firewall/security-wall between the OS and the internet.

+++ A "HIPS" is a firewall/security-wall between the OS and its kernel.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #7  
Old April 16th, 2009, 05:15 AM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,457
Default Re: Is hips a firewall?

Quote:
Originally Posted by bellgamin
+++ A "convential firewall" is a firewall/security-wall between the OS and the internet.

+++ A "HIPS" is a firewall/security-wall between the OS and its kernel.

I'm not sure about the 'conventional'.

For example, the McAfee firewall is at least partly 'rooted' in the OS.

That may be true for others also.

FYI, McAfee has some limited HIPS features, but they are not part of the firewall.
  #8  
Old April 16th, 2009, 01:58 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 3,743
Default Re: Is hips a firewall?

Quote:
Originally Posted by Fly
For example, the McAfee firewall is at least partly 'rooted' in the OS.
Sheesh!

I was not talking about where a firewall's code is "rooted." I was referring to the areas PROTECTED by a conventional firewall, as compared to the areas protected by a classic HIPS.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #9  
Old April 16th, 2009, 04:54 PM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,457
Default Re: Is hips a firewall?

Quote:
Originally Posted by bellgamin
Sheesh!

I was not talking about where a firewall's code is "rooted." I was referring to the areas PROTECTED by a conventional firewall, as compared to the areas protected by a classic HIPS.

Taken that way, you are right
 

Wilders Security Forums > Security Software > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 11:50 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums