|
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM Andrew Plato (aplato anitian com) (12 replies) Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM SecurIT Informatique Inc. (securit iquebec com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM Olaf Gellert (og pre-secure de) (2 replies) Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM SecurIT Informatique Inc. (securit iquebec com) (2 replies) RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM Brian Taylor (drak3 attbi com) (1 replies) Re: Is IDS/IPS worthless? Feb 21 2004 12:05AM Mike Lyman (mlyman-security comcast net) (2 replies) |
|
|
Privacy Statement |
>admin behind the IDS/IPS devices have to be considered. Without a
>skillful security guy looking at the outputs from the IDS/IPS, the
>IDS/IPS is almost worthless as a monitoring device without real people
>looking at the monitors.
Far less so, really. A closed circuit TV with a tape loop is useful even
if nobody looks at it, because the log is a handy thing to have after an
event has happened. An unmaintained IDS isn't even that useful because
it won't have up-to-date signatures and won't have any knowledge of
evolving protocols.
If you step back a little bit this discussion is somewhat amusing--the
choir talking amongst themselves about the absolute need for a strong
tenor section, even for a one-man-band. Comments like "IDS is essential"
just don't make sense. Is IDS essential in some environments? Sure. But
for a small business that doesn't even have a full time IT guy it's a
silly proposition. Even at a not-so-small business IT dollars are finite
and there really just might not be money for IDS--the choice might be
"guy to watch IDS" or "guy to install patch". Are such sites evil
cancers that should be cut off the net? No, of course not. In the real
world there are risks and there are mitigations and sometimes it takes a
hard call to determine where to put resources. IDS dogma (or anti-IDS
dogma) isn't a path to a reasonable solution.
Mike Stone
------------------------------------------------------------------------
---
------------------------------------------------------------------------
---
[ reply ]