Simple way to test an IPS device
Let me preclude this discussion by saying that I am fairly new to security. I know the basics but nothing advanced.
Here is the situation: We are currently testing ISS's Proventia GX4002 IPS device on our production corporate network. The device is running in simulation mode, meaning that it is not blocking any traffic but it will tell you what traffic would have been blocked. The device is sitting directly behind our firewall inspecting all traffic in and out of it. There are going to be two other devices that we evaluate as well. ( McAfee and Juniper )
Besides getting a feel for the GUI layout and playing with the settings. I would like to run a simple test against all three of the devices. I want to send it known exploit traffic and see how it reacts. Logging the reaction from all three devices will help in the evaluation.
My question is how can I do this? What is a simple exploit or vulnerability that I send to my network that will pass the firewall and hopefully get logged by the IPS. Maybe something over port 80 to get through the firewall?
Maybe I'll have to send the exploit from a machine on the LAN out. Then I will be hitting the IPS device first before the firewall.
My brain is mush from all this thinking.......
Please set me straight.....
Thanks in advance for the tips....