Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Focus on IDS
Is IDS/IPS worthless? Feb 20 2004 04:31PM
Andrew Plato (aplato anitian com) (12 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 06:35PM
SecurIT Informatique Inc. (securit iquebec com) (1 replies)
RE: Is IDS/IPS worthless? Feb 23 2004 10:29PM
Martin (mleroux lincsat com)
RE: Is IDS/IPS worthless? Feb 23 2004 05:38PM
Wolfpaw - Dale Corse (admin-lists wolfpaw net)
Re: Is IDS/IPS worthless? Feb 23 2004 02:35PM
Pablo Scherer (pablo_scherer yahoo com)
RE: Is IDS/IPS worthless? Feb 23 2004 11:02AM
Oscar Kooijman (oscar kooijman chello nl)
Re: Is IDS/IPS worthless? Feb 21 2004 11:53PM
Olaf Gellert (og pre-secure de) (2 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 11:24PM
Mike Hoskins (mike adept org)
Re: Is IDS/IPS worthless? Feb 23 2004 08:09PM
SecurIT Informatique Inc. (securit iquebec com) (2 replies)
Re: Is IDS/IPS worthless? Feb 24 2004 04:35PM
Xiaoyong Wu (xwu anr mcnc org) (1 replies)
Re: Is IDS/IPS worthless? Feb 25 2004 03:42AM
Michael Stone (mstone mathom us)
On Tue, Feb 24, 2004 at 11:35:47AM -0500, Xiaoyong Wu wrote:
>admin behind the IDS/IPS devices have to be considered. Without a
>skillful security guy looking at the outputs from the IDS/IPS, the
>IDS/IPS is almost worthless as a monitoring device without real people
>looking at the monitors.

Far less so, really. A closed circuit TV with a tape loop is useful even
if nobody looks at it, because the log is a handy thing to have after an
event has happened. An unmaintained IDS isn't even that useful because
it won't have up-to-date signatures and won't have any knowledge of
evolving protocols.

If you step back a little bit this discussion is somewhat amusing--the
choir talking amongst themselves about the absolute need for a strong
tenor section, even for a one-man-band. Comments like "IDS is essential"
just don't make sense. Is IDS essential in some environments? Sure. But
for a small business that doesn't even have a full time IT guy it's a
silly proposition. Even at a not-so-small business IT dollars are finite
and there really just might not be money for IDS--the choice might be
"guy to watch IDS" or "guy to install patch". Are such sites evil
cancers that should be cut off the net? No, of course not. In the real
world there are risks and there are mitigations and sometimes it takes a
hard call to determine where to put resources. IDS dogma (or anti-IDS
dogma) isn't a path to a reasonable solution.

Mike Stone

------------------------------------------------------------------------
---
------------------------------------------------------------------------
---

[ reply ]
Re: Is IDS/IPS worthless? Feb 23 2004 10:48PM
Olaf Gellert (og pre-secure de) (1 replies)
Re: Is IDS/IPS worthless? Feb 24 2004 03:19AM
SecurIT Informatique Inc. (securit iquebec com)
Re: Is IDS/IPS worthless? Feb 21 2004 09:04PM
Andy Cuff (lists securitywizardry com) (1 replies)
Re: Is IDS/IPS worthless? Feb 23 2004 11:12PM
Mike Hoskins (mike adept org)
Re: Is IDS/IPS worthless? Feb 21 2004 03:40PM
Michael Stone (mstone mathom us)
RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM
Brian Taylor (drak3 attbi com) (1 replies)
RE: Is IDS/IPS worthless? Feb 24 2004 02:06AM
Fergus Brooks (fergusb evolve-online com) (1 replies)
RE: Is IDS/IPS worthless? Feb 24 2004 01:03PM
Duston Sickler (dustons charter net)
RE: Is IDS/IPS worthless? Feb 21 2004 03:13PM
Omar Herrera (oherrera prodigy net mx)
Re: Is IDS/IPS worthless? Feb 21 2004 02:27PM
Konrad Rieck (kr roqe org)
Re: Is IDS/IPS worthless? Feb 21 2004 01:30AM
Josh Tolley (josh raintreeinc com)
Re: Is IDS/IPS worthless? Feb 21 2004 12:05AM
Mike Lyman (mlyman-security comcast net) (2 replies)
Re: Is IDS/IPS worthless? Feb 26 2004 09:11AM
Stefano Zanero (stefano zanero ieee org) (1 replies)
Re: Is IDS/IPS worthless? Mar 02 2004 11:21PM
George Capehart (gwc acm org)
RE: Is IDS/IPS worthless? Feb 24 2004 01:43AM
Fergus Brooks (fergusb evolve-online com)







 

Privacy Statement
Copyright 2008, SecurityFocus