| Image: Unsplash |
Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also roaming elsewhere in the house. The owner had, very helpfully, left out a spray bottle of organic pesticide. But I didn't necessarily want the critters dead; I just wanted them to stay away.
I don't
remember how or why, but I got the idea to rub the counter with half a lemon.
And it worked! The other half, which I placed along their path, worked just as
well as a magic shield.
At home
we have ant trouble too. Fortunately not indoors, but they are undermining our
garden patio. After discovering this new wonder remedy, I sent an order home
from Croatia to stock up on lemons in advance – they happened to be on sale.
Once home, I ran to the garden to see how much lemon juice I'd need. Not an ant
in sight. Not a single one. Rather deflated, over the following weeks we worked
our way through the lemons bit by bit in our daily dose of orange juice.
This
whole story resurfaced recently when someone from Groningen, in an Italian
restaurant in London, asked me what the word for ‘ant’ is in Limburgish (a dialect
from the southernmost province). We were there with a group of fellow attendees
from a security conference, and ‘naturally’ my table companions decided I
should go and capture those ants in a blog post.
They
thought they were helping me along with the term intrusion detection, but in hindsight
their Guinness levels may have been running a bit high at that point. What I'd
actually needed wasn't intrusion detection at all, but intrusion prevention.
The detection had been done with our own eyes; the prevention, with lemons.
So, what
do intrusion detection and intrusion prevention systems (IDS/IPS) actually do?
The names give it away: one only flags things, the other also steps in. Say
someone tries to log in with your user ID ten times in quick succession (a
hypothetical example, since in most systems you wouldn't even get that many
attempts). An IDS flags this and puts up a red flag on a screen, hoping someone
from security notices it. An IPS goes a step further: because that many failed
login attempts isn't normal, it assumes a break-in attempt and blocks your
account. Great, you think, just give me an IPS then, I don't need an IDS
anymore.
As
always, though, it's more nuanced than that. Intervening comes at a price. What
if it was actually you logging in, but you'd accidentally hit the caps lock
key, so upper and lower case ended up reversed in the password field? An IPS
would then lock out the legitimate user, while an IDS alert would instead get
someone to call you and ask if something's wrong. By that time you'd probably
have spotted the caps lock light, smacked yourself on the forehead, and picked
up right where you left off.
You'd
also want a system like this to monitor whether large amounts of data are being
copied (hello, Odido). But that doesn't have to be malicious – maybe an
administrator is copying data as part of a legitimate job. You wouldn't want
the whole thing shut down without question. But then again, maybe you would
want exactly that if such a bulk action happens at three in the morning under
the account of some random person (which does raise the question of whether that
should even be possible in the first place, but that's a different story).
In
short, you want a combination of IDS and IPS. The market has picked up on that
too, since the line between IDS and IPS is blurring; modern products come with
both IDS and IPS capabilities. But if you ever come across the abbreviations,
at least now you know what's behind them.
And oh
yes, that (South) Limburgish word for ant: it's oamezeek (ˈɔːməˌzeːk).
And in the big bad world…
- police arrested a suspected ShinyHunters ringleader, possibly linked to the Odido hack.
- ShinyHunters turns out to be
basically just a brand. [DUTCH]
- digital sovereignty still isn't really taking shape at EU institutions. [DUTCH]
- a carrier pigeon isn't the safest way to transport data.
- there's heated speculation over just how autonomously that hacking AI really operated.
- the European Parliament has once again rejected the mass scanning of our communications.
- the records of millions of US military personnel have been stolen.
- the ethical hackers of DIVD have now been hacked themselves.
- this time it's not the hacked company being extorted, but its customers. [DUTCH]