|
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM Andrew Plato (aplato anitian com) (12 replies) Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM SecurIT Informatique Inc. (securit iquebec com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM Olaf Gellert (og pre-secure de) (2 replies) Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM SecurIT Informatique Inc. (securit iquebec com) (2 replies) RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM Brian Taylor (drak3 attbi com) (1 replies) |
|
Privacy Statement |
> So this speaker then challenged me to come up with verifiable metrics. I
> replied that he would have to define what metrics he wants? What does he
> consider a "viable metric" for performance. He said "did they sell more
> products, make more money?" I replied "why is that the only metric that
Standard security ROI question when security doesn't have an ROI unless
you're selling security. Do locks on the doors help you sell more
product (unless you sell locks) or sprinkler heads in the ceilings help
you make more money?
> What is happening here? Anybody have any idea why there is a growing
> "anti-IDS" attitude. Is it the failure of IDS to produce value in an
I think most people approach IDS/IPS to stop hacking and to stop virus
and worms and they just can't do that job 100%. You can throw all the
resources you want at IDS and it still won't be able to prevent all
security breaches. From that point of view, it's a bottomless pit. You
can put in as many sensors as you want and put as many people watching
the data as you want and you still won't stop everything.
There are realistic approaches and values for IDS/IPS to be had for a
reasonable investment. Unfortunately they are not marketed that way or
priced that way. (well for the most part they aren't priced that way) I
think too many have fallen for the marketing and reality has long since
set in. That may bring some reality to the marketing and the pricing.
--
Mike Lyman <mlyman-security (at) comcast (dot) net [email concealed]>
------------------------------------------------------------------------
---
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
Protect your network with the comprehensive security solution that integrates
six applications for ease of use and lower TCO.
Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.
Download 30-day evaluation at:
http://www.securityfocus.com/sponsor/Astaro_focus-ids_040219
------------------------------------------------------------------------
---
[ reply ]