|
Focus on IDS
ROI on IDS/IPS products Feb 27 2009 05:08PM Ravi Chunduru (ravi is chunduru gmail com) (5 replies) Re: ROI on IDS/IPS products Mar 04 2009 12:55PM aditya mukadam (aditya mukadam gmail com) (1 replies) Re: ROI on IDS/IPS products Feb 28 2009 12:17AM Frank Knobbe (frank knobbe us) (1 replies) Re: ROI on IDS/IPS products Mar 02 2009 06:36PM Jeremy Bennett (jeremyfb mac com) (1 replies) Re: ROI on IDS/IPS products Mar 02 2009 07:21PM Stefano Zanero (s zanero securenetwork it) (2 replies) Re: ROI on IDS/IPS products Mar 03 2009 04:01PM Webmaster 003 (webmaster networkdefense biz) (2 replies) Re: ROI on IDS/IPS products Mar 05 2009 02:48AM Joel Jaeggli (joelja bogus com) (2 replies) Re: ROI on IDS/IPS products Mar 05 2009 05:01PM Joel M Snyder (Joel Snyder Opus1 COM) (1 replies) Re: ROI on IDS/IPS products Mar 06 2009 01:56AM Ravi Chunduru (ravi is chunduru gmail com) (1 replies) Re: ROI on IDS/IPS products Feb 27 2009 06:26PM Jeff Kell (jeff-kell utc edu) (3 replies) Re: ROI on IDS/IPS products Feb 28 2009 10:20PM Ray (rpesek hotmail com) (1 replies) RE: Re: ROI on IDS/IPS products Mar 02 2009 05:26PM Brandon Louder (Brandon Louder mckennan org) (1 replies) |
|
Privacy Statement |
All too often an org will minimize cost at the personnel level by leveraging staff already on board but maybe not qualified for the role. I would also make the conjecture that there was limited buy in of the need for IDS/IPS in the environment. But, Aditya makes the point, "what are you protecting"? The President or ... the junior analyst =) Maybe they did not need it in that environment. I am assuming a "large telecom" has many segments in their network, some of which would absolutely need IDS/IPS. Others... maybe not so much.
jk
-----Original Message-----
From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On Behalf Of aditya mukadam
Sent: Wednesday, March 04, 2009 7:55 AM
To: focus-ids (at) securityfocus (dot) com [email concealed]
Cc: Ravi Chunduru
Subject: Re: ROI on IDS/IPS products
It was felt that they did not find enough ROI to
> justify 2 dedicated personnel to monitor and analyze IDS/IPS logs and
> reports. It apperas that no major incidents were detected by network
> IPS devices. i also was told that these IPS devices are from industry
> leaders.
I read the above with below example :
A residential building has a gate,wall and few security personnel for
safety against theft etc. In two years, there was no major theft or
issues and hence the residents decided to remove the building gate,
security personnel ! Oh yes, the security guards were black cat
commandos !
Your discussion with the security administrator was very interesting
however it would be good to know:
1) How and were are the IPSs placed in the network ?
2) What Signature profile are they using for these IPSs ? Many IPSs
comes with default settings for low detection.
3) Did they tune the IPSs as per their own requirement ?
4) How often they patched the IPSs ?
Lastly, are the IPSs purchased because they were needed *or* the
company was fooled to buy it or had budget/ policies/ vendor
commitment to buy it ?
It all depends what are you safe guarding !
For example: A common man's residential building will have 1 security
guard however the President's residence will have range of security
gadgets, various check points, many many security guards !!!
Thanks,
Aditya Govind Mukadam
On Fri, Feb 27, 2009 at 10:38 PM, Ravi Chunduru
<ravi.is.chunduru (at) gmail (dot) com [email concealed]> wrote:
> I was talking to a junior security administartor working for a big
> telecom company. He said something which is worrying. After few
> years of IPS deployment in particular department, they decided to
> remove IPS devices. It was felt that they did not find enough ROI to
> justify 2 dedicated personnel to monitor and analyze IDS/IPS logs and
> reports. It apperas that no major incidents were detected by network
> IPS devices. they felt that signature coverage is either poor or not
> timely. i also was told that these IPS devices are from industry
> leaders.
>
> Can you share your experiences? Any examples of successful detection
> and prevention of major attacks and penetration by IPS devices.
>
> Thanks
> Ravi
>
>
>
[ reply ]