Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM
Andrew Plato (aplato anitian com) (12 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM
SecurIT Informatique Inc. (securit iquebec com) (1 replies)
RE: Is IDS/IPS worthless? Feb 23 2004 10:29PM
Martin (mleroux lincsat com)
RE: Is IDS/IPS worthless? Feb 23 2004 05:38PM
Wolfpaw - Dale Corse (admin-lists wolfpaw net)
Re: Is IDS/IPS worthless? Feb 23 2004 02:35PM
Pablo Scherer (pablo_scherer yahoo com)
RE: Is IDS/IPS worthless? Feb 23 2004 11:02AM
Oscar Kooijman (oscar kooijman chello nl)
Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM
Olaf Gellert (og pre-secure de) (2 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 11:24PM
Mike Hoskins (mike adept org)
Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM
SecurIT Informatique Inc. (securit iquebec com) (2 replies)
Re: Is IDS/IPS worthless? Feb 24 2004 04:35PM
Xiaoyong Wu (xwu anr mcnc org) (1 replies)
Re: Is IDS/IPS worthless? Feb 25 2004 03:42AM
Michael Stone (mstone mathom us)
Re: Is IDS/IPS worthless? Feb 23 2004 10:48PM
Olaf Gellert (og pre-secure de) (1 replies)
Re: Is IDS/IPS worthless? Feb 24 2004 03:19AM
SecurIT Informatique Inc. (securit iquebec com)
Re: Is IDS/IPS worthless? Feb 21 2004 09:04PM
Andy Cuff (lists securitywizardry com) (1 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 11:12PM
Mike Hoskins (mike adept org)
Re: Is IDS/IPS worthless? Feb 21 2004 03:40PM
Michael Stone (mstone mathom us)
On Fri, Feb 20, 2004 at 08:31:56AM -0800, Andrew Plato wrote:
>What is happening here? Anybody have any idea why there is a growing
>"anti-IDS" attitude.

Because they're very resource intensive with no clear benefit. You can
get by in most IT projects with someone who's barely competent and get
some kind of useful result. (E.g., the network admin managed to plug
cables into a switch and pass traffic.) The best a barely competent IDS
admin with an out-of-the-box IDS config can say is "look, we're being
attacked". And the bottom line is that, all claims of "characterizing
network activity" aside, nobody really cares to know that their network
is being attacked. Even without an IDS I can tell you that your network
is being attacked *right now*. The thing I really want to know is
whether any of the attacks are succeeding--and that's something that
takes a lot more time, skill, and product configuration. IDS vendors
have shot themselves in the foot by creating a lot of signatures that do
nothing more than go "ding!" when they see an attack packet--on a
reasonably busy network all you get is a lot of useless "ding!"s.

Mike Stone

------------------------------------------------------------------------
---
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that integrates
six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.securityfocus.com/sponsor/Astaro_focus-ids_040219
------------------------------------------------------------------------
---

[ reply ]
RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM
Brian Taylor (drak3 attbi com) (1 replies)
RE: Is IDS/IPS worthless? Feb 24 2004 02:06AM
Fergus Brooks (fergusb evolve-online com) (1 replies)
RE: Is IDS/IPS worthless? Feb 24 2004 01:03PM
Duston Sickler (dustons charter net)
RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM
Omar Herrera (oherrera prodigy net mx)
Re: Is IDS/IPS worthless? Feb 21 2004 02:27PM
Konrad Rieck (kr roqe org)
Re: Is IDS/IPS worthless? Feb 21 2004 01:30AM
Josh Tolley (josh raintreeinc com)
Re: Is IDS/IPS worthless? Feb 21 2004 12:05AM
Mike Lyman (mlyman-security comcast net) (2 replies)
Re: Is IDS/IPS worthless? Feb 26 2004 09:11AM
Stefano Zanero (stefano zanero ieee org) (1 replies)
Re: Is IDS/IPS worthless? Mar 02 2004 11:21PM
George Capehart (gwc acm org)
RE: Is IDS/IPS worthless? Feb 24 2004 01:43AM
Fergus Brooks (fergusb evolve-online com)







 

Privacy Statement
Copyright 2008, SecurityFocus