42. Evading IDS, Firewalls and Honeypots – Detection Games
42.1 IDS vs IPS vs Firewall vs Honeypot – Why Each Exists
Thodkyaat char boxes – interview madhe mix naka:
| Control | Job | CIA angle |
|---|---|---|
| Firewall | Allow / deny by policy (ports, IPs, state, app-ID on NGFW) | Mostly availability of the path + reduce attack surface |
| IDS | Detect and alert (often out-of-band / tap) | Integrity + confidentiality (गोपनीयता) – "someone is poking us" |
| IPS | Detect and inline block (can drop; also can break traffic if noisy) | Same + prevention – tune or you DoS yourself |
| Honeypot | Fake service / fake net that nobody legitimate should touch | Detection by deception – high-confidence "this is hostile" |
Firewall = gate. IDS = CCTV + guard who shouts. IPS = gate that slams. Honeypot = dummy godown in Pune that only thieves open. Samjla ka?
Red evasion (चुकवणे) = slip past the CCTV or look like staff. Blue job = assume Red will try; design layers so one miss is not game over. APT-class lesson (next box): inbound firewall "green" asel pan outbound C2 quiet asel tar Red already inside.
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Counts on inbound-only firewall; C2 goes out as "web" | Egress filtering; proxy; IDS on outbound DNS/HTTP |
| Hopes IDS is tap with no one watching alerts | 24x7 review / SIEM; tune, don't mute |
| Avoids real servers; hunts until something answers | Honeypot + alert on first touch; shrink real listen ports |
Ravindra Bagale's Tip
Students say "the firewall is ON, so no need for an IDS". When the firewall policy misses something, the IDS/IPS is a second pair of eyes. Use both. One line for the interview: "Firewall enforces policy; IDS/IPS tells me when policy or payload is abused." Remember this.
Ravindra Bagale's Tip – मराठी
Students "firewall ON = IDS नको" म्हणतात. Firewall policy चुकली की IDS/IPS हा second pair of eyes. दोन्ही. Interview साठी एक line: "Firewall enforces policy; IDS/IPS tells me when policy or payload is abused." हे लक्षात ठेवा.
Ravindra Bagale's Tip – हिंदी
Students कहते हैं "firewall ON = IDS नहीं चाहिए". Firewall policy चूकी तो IDS/IPS second pair of eyes है. दोनों. Interview के लिए एक line: "Firewall enforces policy; IDS/IPS tells me when policy or payload is abused." यह याद रखो.
Lab
Notes madhe 5-row table: firewall | IDS | IPS | honeypot | SIEM – ek-ek line def + one failure mode (e.g. IPS false positive drops payroll). Fictional Sahyadri Traders (Pune) – Raja mhanto "port 80/443 open, bas". Write 6 sentences: which CIA properties still need IDS on egress.
Real incident: Mandiant APT1 report (2013)
In 2013, Mandiant published the public APT1 report on a long-running cyber-espionage campaign. A widely cited technical lesson for this chapter: APT-style backdoors typically start outbound connections to command-and-control (C2), because perimeter firewalls are generally stronger at blocking inbound unsolicited sessions than at stopping malware already inside from phoning home. Mandiant also released a large public set of indicators (domains, IPs, hashes – thousands, as reported in the report and accompanying materials) so defenders could hunt and write detections. Weakness: inbound-centric perimeter thinking; custom backdoors that did not match casual "block known bad ports" rules. Defence: egress control, outbound IDS/proxy logs, indicator-driven hunting, assume breach. Source: Mandiant APT1: Exposing One of China's Cyber Espionage Units (2013) and related public briefings (verify; say "reported" for campaign scale).