Focus on IDS
ROI on IDS/IPS products Feb 27 2009 05:08PM
Ravi Chunduru (ravi is chunduru gmail com) (5 replies)
Re: ROI on IDS/IPS products Mar 04 2009 12:55PM
aditya mukadam (aditya mukadam gmail com) (1 replies)
RE: ROI on IDS/IPS products Mar 05 2009 03:22PM
Kirk, James P. (JAMES P KIRK saic com)
Re: ROI on IDS/IPS products Feb 28 2009 03:11PM
Mark Stingley (infosec altsec info)
Re: ROI on IDS/IPS products Feb 28 2009 12:17AM
Frank Knobbe (frank knobbe us) (1 replies)
On Fri, 2009-02-27 at 09:08 -0800, Ravi Chunduru wrote:
> I was talking to a junior security administartor working for a big
> telecom company. He said something which is worrying. After few
> years of IPS deployment in particular department, they decided to
> remove IPS devices. It was felt that they did not find enough ROI to
> justify 2 dedicated personnel to monitor and analyze IDS/IPS logs and
> reports. It apperas that no major incidents were detected by network
> IPS devices. they felt that signature coverage is either poor or not
> timely. i also was told that these IPS devices are from industry

Discussion around the term ROI aside, your question should not have been
about "ROI on IDS/IPS products", but rather about "IDS/IPS
*deployments*".

You can have a great product that works really well (Snort comes to
mind), but deploy it completely wrong. While the "ROI" of the product
exists, the deployment makes it a complete waste of funds.

I'm not sure which product you are referring to (though I can make a
good guess :), and yes, there are products that conform to their
companies marketing material and get you a check-box on your compliance
audits, but are actually worthless. Other products are great, but again,
if they are not *deployed* correctly and/or *used* correctly, then these
deployments are also a waste of time and money.

I think too many people expect to buy an IDS/IPS off the shelf, read the
manual, get it set up, and think the task is done. IDS/IPS boxes are
tricky and require expertise to properly configure and use. If that
expertise doesn't exist in your organization, hire someone that does
have the expertise and can help not just implementing the IDS/IPS, but
also assist creating a group that can actually manage and use it on a
continuous basis.

Cheers,
Frank

--
It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.10 (FreeBSD)

iD8DBQBJqIKJpIc56HlJ1YARAtHdAJwJOMPRsl2tlX8SD4YKpi5UOGyyNQCdFqro
zo8IHUQLZb/0IAa2lrDd7dE=
=wSYH
-----END PGP SIGNATURE-----

[ reply ]
Re: ROI on IDS/IPS products Mar 02 2009 06:36PM
Jeremy Bennett (jeremyfb mac com) (1 replies)
Re: ROI on IDS/IPS products Mar 02 2009 07:21PM
Stefano Zanero (s zanero securenetwork it) (2 replies)
Re: ROI on IDS/IPS products Mar 03 2009 04:01PM
Webmaster 003 (webmaster networkdefense biz) (2 replies)
Re: ROI on IDS/IPS products Mar 05 2009 02:48AM
Joel Jaeggli (joelja bogus com) (2 replies)
Re: ROI on IDS/IPS products Mar 05 2009 05:01PM
Joel M Snyder (Joel Snyder Opus1 COM) (1 replies)
Re: ROI on IDS/IPS products Mar 06 2009 01:56AM
Ravi Chunduru (ravi is chunduru gmail com) (1 replies)
Re: ROI on IDS/IPS products Mar 06 2009 03:05AM
Joel Jaeggli (joelja bogus com)
Re: ROI on IDS/IPS products Mar 05 2009 12:51PM
Webmaster 003 (webmaster networkdefense biz)
Re: ROI on IDS/IPS products Mar 03 2009 05:11PM
Joel M Snyder (Joel Snyder Opus1 COM)
Re: ROI on IDS/IPS products Mar 02 2009 08:09PM
Jeremy Bennett (jeremyfb mac com) (2 replies)
Re: ROI on IDS/IPS products Mar 06 2009 05:18AM
Stefano Zanero (s zanero securenetwork it)
Re: ROI on IDS/IPS products Mar 03 2009 06:54AM
Scott (opiesan gmail com)
Re: ROI on IDS/IPS products Feb 27 2009 06:47PM
Martin Roesch (roesch sourcefire com) (1 replies)
RE: ROI on IDS/IPS products Feb 27 2009 07:52PM
Pete Lindstrom (petelind spiresecurity com)
Re: ROI on IDS/IPS products Feb 27 2009 06:26PM
Jeff Kell (jeff-kell utc edu) (3 replies)
Re: ROI on IDS/IPS products Feb 28 2009 10:20PM
Ray (rpesek hotmail com) (1 replies)
RE: Re: ROI on IDS/IPS products Mar 02 2009 05:26PM
Brandon Louder (Brandon Louder mckennan org) (1 replies)
Re: Re: ROI on IDS/IPS products Mar 02 2009 11:57PM
Ray (rpesek hotmail com)
Re: ROI on IDS/IPS products Feb 28 2009 12:22AM
Joel Jaeggli (joelja bogus com)
Re: ROI on IDS/IPS products Feb 27 2009 08:29PM
Aaron Turner (synfinatic gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus