Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Don't blame the IDS
Don Parker, 2007-11-09

Some years ago, I remember reading a press release from the Gartner Group. It was about intrusion detection systems (IDS) offering little return for the monetary investment in them and furthermore, that this very same security technology would be obsolete by the year 2005. A rather bold statement and an even bolder prediction on their part.

Comments Mode:
Don't blame the IDS 2007-11-10
Anonymous
Don't blame the IDS 2007-11-11
Param
Yes, let's blame the IDS 2007-11-12
assurbanipal (1 replies)
Re: Yes, let's blame the IDS 2007-11-13
Anonymous
Don't blame the IDS 2007-11-12
Gandalf
""""To do it well you need to have a large body of knowledge. Not only that, you must also take the time to properly tune the IDS to its environment.""""""

key point here...

You see, Don , what they fail to see in addition to the above comment, is that IDS is a live-reaction system , which will offer enough protection against many attacks, and at the same time offer a good ROI,since suffering a hacking/cracking blow , and use a CSIRT will cause a triple impact on their budget.

One is to maintain and apply CSIRT policies and reactions.
Second is to restore all functionality and check all things.

ok... so far same happens with an IDS... the third though blow is critical.

Reputation impact. A network which has been altered/compromised from an attacker, gets a "negative reputation" which indeed affects all kinds of parameters in management and marketing levels.

They should remember that LAN is there to provice services and clients expect to be safe. IDS is cappable to offer this in real time and even as a "show only" precaution measure that company took. Something to show of to worrying clients.

Unless you expect them to be happy enough by saying a have a very good policy , right after we established that we have been attacked!!!

Gandalf

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/457/34791#34791
Don't blame the IDS 2007-11-12
Anonymous (1 replies)
Re: Don't blame the IDS 2007-11-13
Ryan Wegner
Don't blame the IDS 2007-11-13
Anonymous
Don't blame the IDS 2007-11-14
John Sloan (1 replies)
Re: Don't blame the IDS 2007-11-17
Ari Takanen (Codenomicon)
Don't blame the IDS 2007-11-19
Anonymous
NSM == IDS++ 2007-11-26
Hanashi
Don't blame the IDS 2009-08-14
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus