|
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM Andrew Plato (aplato anitian com) (12 replies) Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM SecurIT Informatique Inc. (securit iquebec com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM Olaf Gellert (og pre-secure de) (2 replies) Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM SecurIT Informatique Inc. (securit iquebec com) (2 replies) RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM Brian Taylor (drak3 attbi com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 12:05AM Mike Lyman (mlyman-security comcast net) (2 replies) |
|
|
Privacy Statement |
>What is happening here? Anybody have any idea why there is a growing
>"anti-IDS" attitude.
Because they're very resource intensive with no clear benefit. You can
get by in most IT projects with someone who's barely competent and get
some kind of useful result. (E.g., the network admin managed to plug
cables into a switch and pass traffic.) The best a barely competent IDS
admin with an out-of-the-box IDS config can say is "look, we're being
attacked". And the bottom line is that, all claims of "characterizing
network activity" aside, nobody really cares to know that their network
is being attacked. Even without an IDS I can tell you that your network
is being attacked *right now*. The thing I really want to know is
whether any of the attacks are succeeding--and that's something that
takes a lot more time, skill, and product configuration. IDS vendors
have shot themselves in the foot by creating a lot of signatures that do
nothing more than go "ding!" when they see an attack packet--on a
reasonably busy network all you get is a lot of useless "ding!"s.
Mike Stone
------------------------------------------------------------------------
---
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
Protect your network with the comprehensive security solution that integrates
six applications for ease of use and lower TCO.
Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.
Download 30-day evaluation at:
http://www.securityfocus.com/sponsor/Astaro_focus-ids_040219
------------------------------------------------------------------------
---
[ reply ]