# Can Zeek be installed as in-line IPS?

**URL:** <https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637>\
**Category:** Zeek\
**Created:** [March 18, 2019, 9:49am UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637 "2019-03-18T09:49:32Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dario\_Mohaddes](https://avatars.discourse-cdn.com/v4/letter/d/f05b48/32.png) [@Dario\_Mohaddes](https://community.zeek.org/u/Dario_Mohaddes)\
**Post date:** [March 18, 2019, 9:49am UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/1 "2019-03-18T09:49:32Z")

</div>

I’m starting a comparison paper about inline Network IPS. I was looking for an opensource anomaly-based detection engine with IPS capabilities. The easiest choice seemed Zeek but from the website user-manual it doesn’t look like it actually supports packets dropping, instead can only work as IDS. Digging a bit online I found a lot of confusion and contradictions with people asserting either that is possible or not but none giving a practical example. I have scraped a multitude of academic and research papers but they haven’t help… I was wondering if anyone can tell me if is feasible before wasting hours trying to do something that is not. Any help or insight is much appreciated. Thank you.

---

<div class="post-metadata">

**Author:** ![Joe\_Blow](https://avatars.discourse-cdn.com/v4/letter/j/dec6dc/32.png) [@Joe\_Blow](https://community.zeek.org/u/Joe_Blow)\
**Post date:** [March 18, 2019, 11:55am UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/2 "2019-03-18T11:55:03Z")

</div>

Take a look at the netcontrol stuff.

[https://docs.zeek.org/en/latest/frameworks/netcontrol.html](https://docs.zeek.org/en/latest/frameworks/netcontrol.html)

Zeek will talk to other systems to perform the actual action of crushing the connection.

Best hope with that scenario really is that you kill the connection a few packets in, as you’re racing to block on an inline device (router, switch, FW), from another passive system (Zeek). It blurs the line between IDS and IPS because the race condition. Good example is droppers. You might only have subsecond to block. Are you really running an IPS if some packets can get through?

Reactive IDS might be a more apt analogy.

Cheers,

JB

> **From:** [m.dariuz@gmail.com](mailto:m.dariuz@gmail.com)  
> **Sent:** March 18, 2019 6:04 AM  
> **To:** [zeek@zeek.org](mailto:zeek@zeek.org)  
> **Subject:** [Zeek] Can Zeek be installed as in-line IPS?  
>   
> |
> 
> - |

I’m starting a comparison paper about inline Network IPS. I was looking for an opensource anomaly-based detection engine with IPS capabilities. The easiest choice seemed Zeek but from the website user-manual it doesn’t look like it actually supports packets dropping, instead can only work as IDS. Digging a bit online I found a lot of confusion and contradictions with people asserting either that is possible or not but none giving a practical example. I have scraped a multitude of academic and research papers but they haven’t help… I was wondering if anyone can tell me if is feasible before wasting hours trying to do something that is not. Any help or insight is much appreciated. Thank you.

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [March 18, 2019, 3:09pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/3 "2019-03-18T15:09:23Z")

</div>

JB’s answer was great. I’d only add that I don’t think of Zeek as an IDS. Zeek is a network security monitor. It’s designed to describe what’s happening on your network in a mostly neutral way. It’s up to the analyst to use that data for a variety of purposes, one of which could be intrusion detection. Suricata and Snort are more characteristic of an “IDS” because they make judgements about what they see, although Suricata has been integrating ever more NSM functionality by logging DNS, HTTP, etc. as Zeek does.

Aside from web application firewalls, I think the IPS market is fairly dead anyway with the ubiquity of encrypted north-south network traffic.

Sincerely,

Richard

---

<div class="post-metadata">

**Author:** ![Patrick\_Kelley](https://avatars.discourse-cdn.com/v4/letter/p/a87d85/32.png) [@Patrick\_Kelley](https://community.zeek.org/u/Patrick_Kelley)\
**Post date:** [March 18, 2019, 3:30pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/4 "2019-03-18T15:30:57Z")

</div>

Had me all the way until…

“Aside from web application firewalls, I think the IPS market is fairly dead anyway with the ubiquity of encrypted north-south network traffic.”.

I still see the same issues we had on networks 10 years ago. It is reduced, due to HTTPS and some SMTP, sure. Dead… not really.

---

<div class="post-metadata">

**Author:** ![Darren\_S](https://avatars.discourse-cdn.com/v4/letter/d/59ef9b/32.png) [@Darren\_S](https://community.zeek.org/u/Darren_S)\
**Post date:** [March 18, 2019, 4:16pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/5 "2019-03-18T16:16:50Z")

</div>

Yes, exactly. We need to be careful with our messaging on this as a community because the number of threats still seen (and more generally, the amount of metadata from traffic that can be successfully logged to support NSM) is still significant. Richard said “fairly dead” but casual readers and the tech press tend to take that as a soundbyte and parrot it out as “it’s basically all encrypted, don’t worry about it.” I have had customers that have refuse an option to deploy a network sensor like Zeek or Suricata in their environment in the role of NSM sensors because of this erroneous belief (and a convenient chance to save some capex not buying more hardware). It’s disappointing because we see a lot of success detecting badness in other environments so these customers willfully put themselves at a disadvantage to attackers who still operate over cleartext protocols.

- Darren

---

<div class="post-metadata">

**Author:** ![seth](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/seth/32/642_2.png) [@seth](https://community.zeek.org/u/seth)\
**Post date:** [March 18, 2019, 5:02pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/6 "2019-03-18T17:02:20Z")

</div>

To be fair, he did say IPS. In my opinion IPS has always been in a weird spot where the definition isn't terribly clear (block a single packet in-flight? block a connection after a determination is made? ...etc).

I think everyone here will agree that the visibility provided by Zeek is useful even on modern networks and that tail of completely unencrypted traffic is awfully long. 🙂

&nbsp;&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 18, 2019, 5:16pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/7 "2019-03-18T17:16:54Z")

</div>

Concur. Zeek on the perimeter is great for metadata about encrypted sessions. Zeek internally from client/server or Windows Client/Windows Domain Controller will open your eyes to a LOT of traffic you may not have expected.

James

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [March 18, 2019, 5:40pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/8 "2019-03-18T17:40:06Z")

</div>

Yes, as Seth said, I said IPS. Is anyone really deploying IPS now? I only see Palo Alto firewalls, etc.

Sincerely,

Richard

---

<div class="post-metadata">

**Author:** ![Patrick\_Kelley](https://avatars.discourse-cdn.com/v4/letter/p/a87d85/32.png) [@Patrick\_Kelley](https://community.zeek.org/u/Patrick_Kelley)\
**Post date:** [March 18, 2019, 5:49pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/9 "2019-03-18T17:49:50Z")

</div>

Yes. Many.

PCI-DSS 11.4 comes up quite often. Whether we have consensus on the validity and utility of an IPS or not, it comes up in every single PCI audit.

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [March 18, 2019, 6:28pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/10 "2019-03-18T18:28:16Z")

</div>

The PCI requirement is for IDS or IPS, which is unfortunate because they are totally different. I’m surprised IPS is even a market segment anymore. At this point it’s really just a firewall feature. There’s so much more that can be done with a passive observation platform like Zeek, when you don’t have to worry about making line-speed judgements.

Sincerely,

Richard

---

<div class="post-metadata">

**Author:** ![Edgmand\_Craig](https://avatars.discourse-cdn.com/v4/letter/e/838e76/32.png) [@Edgmand\_Craig](https://community.zeek.org/u/Edgmand_Craig)\
**Post date:** [March 18, 2019, 6:39pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/11 "2019-03-18T18:39:51Z")

</div>

Didn’t IDS die circa 2005? J

---

<div class="post-metadata">

**Author:** ![Patrick\_Kelley](https://avatars.discourse-cdn.com/v4/letter/p/a87d85/32.png) [@Patrick\_Kelley](https://community.zeek.org/u/Patrick_Kelley)\
**Post date:** [March 18, 2019, 6:49pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/12 "2019-03-18T18:49:19Z")

</div>

Somedays I wish…

As I sit here reviewing the deployment and Change Management notes for a ASA/FirePower, two SourceFire 7120’s, two 8250’s, and two VM FirePowers.

Orgs are still trying to get ROI on some of this stuff. It’s not AI/ML or Blockchain, but it’s still running.

---

<div class="post-metadata">

**Author:** ![Patrick\_Kelley](https://avatars.discourse-cdn.com/v4/letter/p/a87d85/32.png) [@Patrick\_Kelley](https://community.zeek.org/u/Patrick_Kelley)\
**Post date:** [March 18, 2019, 7:01pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/13 "2019-03-18T19:01:49Z")

</div>

@James Lay

Couldn’t agree more about the metadata and convergence of E/W traffic. Additionally, we’ve used SIP analyzers to validate the implementation of Zeek as a security platform, as it could provide greater visibility into call center traffic.

Showing that it could increase efficiency, while providing a better security posture was a good win.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/can-zeek-be-installed-as-in-line-ips/5637/14 "2022-05-06T15:46:23Z")

</div>


