|
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM Andrew Plato (aplato anitian com) (12 replies) Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM SecurIT Informatique Inc. (securit iquebec com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM Olaf Gellert (og pre-secure de) (2 replies) Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM SecurIT Informatique Inc. (securit iquebec com) (2 replies) RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM Brian Taylor (drak3 attbi com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 12:05AM Mike Lyman (mlyman-security comcast net) (2 replies) |
|
|
Privacy Statement |
> So this speaker then challenged me to come up with verifiable metrics. I
> replied that he would have to define what metrics he wants? What does he
> consider a "viable metric" for performance. He said "did they sell more
> products, make more money?" I replied "why is that the only metric that
> businesses can understand?
IT security is about keeping money - not making it. IDS/IPS reduce the
the probability of an undetected compromise. Depending on your setup,
environment and data such a compromise may result in an enormous
financial loss.
The relation between
...the probability of a successful compromise in respect to the
resulting costs
and
...the probability for a detection in respect to the maintenance
costs of an IDS/IPS solution
form a verifiable metric (unless you talk with someone who can't deal
with probabilities).
Here's nice paper on that topic...
"Cost-Benefit Analysis for Network Intrusion Detection Systems"
http://www.csds.uidaho.edu/director/costbenefit.pdf
Regards,
Konrad
--
Konrad Rieck <kr (at) roqe (dot) org [email concealed]> ------------ http://people.roqe.org/kr
Fingerprint - 7D55 5896 834A A1C8 303C - 8BC5 4C53 3611 C1FA 82F2
[ reply ]