Ravindra BagaleCourses & study guides

42. Evading IDS, Firewalls and Honeypots – Detection Games

42.1 IDS vs IPS vs Firewall vs Honeypot – Why Each Exists

Thodkyaat char boxes – interview madhe mix naka:

Control Job CIA angle
Firewall Allow / deny by policy (ports, IPs, state, app-ID on NGFW) Mostly availability of the path + reduce attack surface
IDS Detect and alert (often out-of-band / tap) Integrity + confidentiality (गोपनीयता) – "someone is poking us"
IPS Detect and inline block (can drop; also can break traffic if noisy) Same + prevention – tune or you DoS yourself
Honeypot Fake service / fake net that nobody legitimate should touch Detection by deception – high-confidence "this is hostile"

Firewall = gate. IDS = CCTV + guard who shouts. IPS = gate that slams. Honeypot = dummy godown in Pune that only thieves open. Samjla ka?

Red evasion (चुकवणे) = slip past the CCTV or look like staff. Blue job = assume Red will try; design layers so one miss is not game over. APT-class lesson (next box): inbound firewall "green" asel pan outbound C2 quiet asel tar Red already inside.

Red team (attacker) does Blue team (defender) detects / stops
Counts on inbound-only firewall; C2 goes out as "web" Egress filtering; proxy; IDS on outbound DNS/HTTP
Hopes IDS is tap with no one watching alerts 24x7 review / SIEM; tune, don't mute
Avoids real servers; hunts until something answers Honeypot + alert on first touch; shrink real listen ports

Ravindra Bagale's Tip

Students "firewall ON = IDS nako" mhantat. Firewall policy miss zali ki IDS/IPS second pair of eyes. Donhi. Interview ek line: "Firewall enforces policy; IDS/IPS tells me when policy or payload is abused." He lakshat theva.

Lab

Notes madhe 5-row table: firewall | IDS | IPS | honeypot | SIEM – ek-ek line def + one failure mode (e.g. IPS false positive drops payroll). Fictional Sahyadri Traders (Pune) – Raja mhanto "port 80/443 open, bas". Write 6 sentences: which CIA properties still need IDS on egress.

Real incident: Mandiant APT1 report (2013)

In 2013, Mandiant published the public APT1 report on a long-running cyber-espionage campaign. A widely cited technical lesson for this chapter: APT-style backdoors typically start outbound connections to command-and-control (C2), because perimeter firewalls are generally stronger at blocking inbound unsolicited sessions than at stopping malware already inside from phoning home. Mandiant also released a large public set of indicators (domains, IPs, hashes – thousands, as reported in the report and accompanying materials) so defenders could hunt and write detections. Weakness: inbound-centric perimeter thinking; custom backdoors that did not match casual "block known bad ports" rules. Defence: egress control, outbound IDS/proxy logs, indicator-driven hunting, assume breach. Source: Mandiant APT1: Exposing One of China's Cyber Espionage Units (2013) and related public briefings (verify; say "reported" for campaign scale).