Focus on IDS
ROI on IDS/IPS products Feb 27 2009 05:08PM
Ravi Chunduru (ravi is chunduru gmail com) (5 replies)
Re: ROI on IDS/IPS products Mar 04 2009 12:55PM
aditya mukadam (aditya mukadam gmail com) (1 replies)
RE: ROI on IDS/IPS products Mar 05 2009 03:22PM
Kirk, James P. (JAMES P KIRK saic com)
Re: ROI on IDS/IPS products Feb 28 2009 03:11PM
Mark Stingley (infosec altsec info)
Re: ROI on IDS/IPS products Feb 28 2009 12:17AM
Frank Knobbe (frank knobbe us) (1 replies)
Re: ROI on IDS/IPS products Mar 02 2009 06:36PM
Jeremy Bennett (jeremyfb mac com) (1 replies)
Re: ROI on IDS/IPS products Mar 02 2009 07:21PM
Stefano Zanero (s zanero securenetwork it) (2 replies)
Re: ROI on IDS/IPS products Mar 03 2009 04:01PM
Webmaster 003 (webmaster networkdefense biz) (2 replies)
Re: ROI on IDS/IPS products Mar 05 2009 02:48AM
Joel Jaeggli (joelja bogus com) (2 replies)
Re: ROI on IDS/IPS products Mar 05 2009 05:01PM
Joel M Snyder (Joel Snyder Opus1 COM) (1 replies)
Re: ROI on IDS/IPS products Mar 06 2009 01:56AM
Ravi Chunduru (ravi is chunduru gmail com) (1 replies)
Re: ROI on IDS/IPS products Mar 06 2009 03:05AM
Joel Jaeggli (joelja bogus com)
Re: ROI on IDS/IPS products Mar 05 2009 12:51PM
Webmaster 003 (webmaster networkdefense biz)
Re: ROI on IDS/IPS products Mar 03 2009 05:11PM
Joel M Snyder (Joel Snyder Opus1 COM)
Re: ROI on IDS/IPS products Mar 02 2009 08:09PM
Jeremy Bennett (jeremyfb mac com) (2 replies)
Re: ROI on IDS/IPS products Mar 06 2009 05:18AM
Stefano Zanero (s zanero securenetwork it)
Re: ROI on IDS/IPS products Mar 03 2009 06:54AM
Scott (opiesan gmail com)
On Mon, Mar 2, 2009 at 3:09 PM, Jeremy Bennett <jeremyfb (at) mac (dot) com [email concealed]> wrote:
>
> On Mar 2, 2009, at 11:21 AM, Stefano Zanero wrote:
>
>
> You assert that the customer 'WILL need to know damn well what they are
> doing.' I assert that if the customer knew what they were doing to the
> degree that you imply they'd be writing their own snort rules. Sourcefire
> has a good product based on this and it has its place in organizations that
> can run it.
> There are many customers that will never have that expertise. They have no
> choice but to trust their vendor to have the expertise necessary to write
> signatures and clearly communicate the efficacy of those signatures. This is
> the bulk of the potential IPS market, those people that want something
> better than a firewall but can't afford to digest 100,000 events per day.
>
> -J

I'm glad you mentioned Sourcefire directly. I've had to manage a few
different brands of IDS/IPS including ISS, Dragon, and Sourcefire now.
As pure IPS they all have the challenge of needing someone qualified
enough to accurately interpret event data and tune down the false
positives. IMO, what helps the Sourcefire product stand out is the
addition of RNA and similar features. The added intelligence RNA
provides dramatically decreases the time and effort and analyst needs
to make an informed decision on the validity of an alert. You still
have to deploy it correctly and employ qualified analysts but if
you're looking for a way to quantify ROI consider how much time (=
$$$) it saves an analyst to have most, if not all, the data they need
to qualify an alert right at their fingertips rather than having to go
and hunt it down or manually correlate it from other sources (ie VA
scans, system inventories, other sys admins). It's still a hard number
to pin down but I think it's worth mentioning.

Disclaimer - No, I don't work for Sourcefire (but if Mr. Roesch would
open a spot on the prof services team we could remedy that). ;-)

Scott

[ reply ]
Re: ROI on IDS/IPS products Feb 27 2009 06:47PM
Martin Roesch (roesch sourcefire com) (1 replies)
RE: ROI on IDS/IPS products Feb 27 2009 07:52PM
Pete Lindstrom (petelind spiresecurity com)
Re: ROI on IDS/IPS products Feb 27 2009 06:26PM
Jeff Kell (jeff-kell utc edu) (3 replies)
Re: ROI on IDS/IPS products Feb 28 2009 10:20PM
Ray (rpesek hotmail com) (1 replies)
RE: Re: ROI on IDS/IPS products Mar 02 2009 05:26PM
Brandon Louder (Brandon Louder mckennan org) (1 replies)
Re: Re: ROI on IDS/IPS products Mar 02 2009 11:57PM
Ray (rpesek hotmail com)
Re: ROI on IDS/IPS products Feb 28 2009 12:22AM
Joel Jaeggli (joelja bogus com)
Re: ROI on IDS/IPS products Feb 27 2009 08:29PM
Aaron Turner (synfinatic gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus