Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM
Andrew Plato (aplato anitian com) (12 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM
SecurIT Informatique Inc. (securit iquebec com) (1 replies)
RE: Is IDS/IPS worthless? Feb 23 2004 10:29PM
Martin (mleroux lincsat com)
RE: Is IDS/IPS worthless? Feb 23 2004 05:38PM
Wolfpaw - Dale Corse (admin-lists wolfpaw net)
Re: Is IDS/IPS worthless? Feb 23 2004 02:35PM
Pablo Scherer (pablo_scherer yahoo com)
RE: Is IDS/IPS worthless? Feb 23 2004 11:02AM
Oscar Kooijman (oscar kooijman chello nl)
Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM
Olaf Gellert (og pre-secure de) (2 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 11:24PM
Mike Hoskins (mike adept org)
Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM
SecurIT Informatique Inc. (securit iquebec com) (2 replies)
Re: Is IDS/IPS worthless? Feb 24 2004 04:35PM
Xiaoyong Wu (xwu anr mcnc org) (1 replies)
Re: Is IDS/IPS worthless? Feb 25 2004 03:42AM
Michael Stone (mstone mathom us)
Re: Is IDS/IPS worthless? Feb 23 2004 10:48PM
Olaf Gellert (og pre-secure de) (1 replies)
Re: Is IDS/IPS worthless? Feb 24 2004 03:19AM
SecurIT Informatique Inc. (securit iquebec com)
Re: Is IDS/IPS worthless? Feb 21 2004 09:04PM
Andy Cuff (lists securitywizardry com) (1 replies)
Hi Andrew,
Lovely topic for the weekend !! What I have written below are just my
feelings on the subject, to help you keep them in perspective I should point
out that I'm very passionate about the use of IDS and IPS and feel similarly
annoyed at these recent opinions. From what you have said you countered his
suggestions very well. I would only add what would the cost to the company
be if it were hacked.

IMHO IDS and IPS are not dead, quite the reverse, but in order to make them
useful they require a degree of continued investment and support. In some
part the vendors are to blame for selling their product to organisations
where they know full well that they won't be supported, in order to make a
fast buck, (puts asbestos suit on). This is not always the case as I've had
some refreshingly pleasant experiences from certain vendors who genuinely
want to ensure that their products are optimised to the environment and
phone periodically offering free visits from their support staff !!!.
The organisations themselves are equally if not more blameworthy for
purchasing the products without fully investigating the issues surrounding
them.

With regard to the business case surely the business in question is
dutybound to assure the integrity of data relating to their customers, in
certain circumstances they are legally bound. Now, the law does not dictate
what products should be in place to provide this assurance and PERHAPS there
is a case for network defense not requiring IDS/IPS to protect their network
because the other methods are so effective. In which case perhaps they will
use their corporate webpage saying "You Are Owned By......" to detect
intrusions, or the Wall Street Journal, it's not quite "near real time" but
highly effective in making those who you don't want to know, know about your
lack of investment in network security. Stats always work well, has anyone
investigated and recorded the drop in share prices following an attack. IDS
per se won't prevent these attacks but at least they may alert the business
to them having occurred and provide sufficient time to put a spin on the
event. Anyone remember the recent defacement that turned out to be a
honeypot ;o)

I consider them essential in today's networks but I like the concept of
defense in depth to run very deep, however, if an IDS or IPS isn't
maintained correctly they can create more problems than they solve, as they
may lull the staff into a false sense of security.

just my 2 cents

-andy
Talisker Security Tools Directory
http://www.securitywizardry.com
----- Original Message -----
From: "Andrew Plato" <aplato (at) anitian (dot) com [email concealed]>
To: <focus-ids (at) securityfocus (dot) com [email concealed]>
Sent: Friday, February 20, 2004 4:31 PM
Subject: Is IDS/IPS worthless?

------------------------------------------------------------------------
---
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that integrates
six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.securityfocus.com/sponsor/Astaro_focus-ids_040219
------------------------------------------------------------------------
---

[ reply ]
Re: Is IDS/IPS worthless? Feb 23 2004 11:12PM
Mike Hoskins (mike adept org)
Re: Is IDS/IPS worthless? Feb 21 2004 03:40PM
Michael Stone (mstone mathom us)
RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM
Brian Taylor (drak3 attbi com) (1 replies)
RE: Is IDS/IPS worthless? Feb 24 2004 02:06AM
Fergus Brooks (fergusb evolve-online com) (1 replies)
RE: Is IDS/IPS worthless? Feb 24 2004 01:03PM
Duston Sickler (dustons charter net)
RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM
Omar Herrera (oherrera prodigy net mx)
Re: Is IDS/IPS worthless? Feb 21 2004 02:27PM
Konrad Rieck (kr roqe org)
Re: Is IDS/IPS worthless? Feb 21 2004 01:30AM
Josh Tolley (josh raintreeinc com)
Re: Is IDS/IPS worthless? Feb 21 2004 12:05AM
Mike Lyman (mlyman-security comcast net) (2 replies)
Re: Is IDS/IPS worthless? Feb 26 2004 09:11AM
Stefano Zanero (stefano zanero ieee org) (1 replies)
Re: Is IDS/IPS worthless? Mar 02 2004 11:21PM
George Capehart (gwc acm org)
RE: Is IDS/IPS worthless? Feb 24 2004 01:43AM
Fergus Brooks (fergusb evolve-online com)







 

Privacy Statement
Copyright 2008, SecurityFocus