Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Don't blame the IDS
Don Parker, 2007-11-09

Some years ago, I remember reading a press release from the Gartner Group. It was about intrusion detection systems (IDS) offering little return for the monetary investment in them and furthermore, that this very same security technology would be obsolete by the year 2005. A rather bold statement and an even bolder prediction on their part.

Comments Mode:
Don't blame the IDS 2007-11-10
Anonymous
Don't blame the IDS 2007-11-11
Param
Yes, let's blame the IDS 2007-11-12
assurbanipal (1 replies)
Re: Yes, let's blame the IDS 2007-11-13
Anonymous
Don't blame the IDS 2007-11-12
Gandalf
Don't blame the IDS 2007-11-12
Anonymous (1 replies)
Re: Don't blame the IDS 2007-11-13
Ryan Wegner
Don't blame the IDS 2007-11-13
Anonymous
Don't blame the IDS 2007-11-14
John Sloan (1 replies)
Re: Don't blame the IDS 2007-11-17
Ari Takanen (Codenomicon)
Don't blame the IDS 2007-11-19
Anonymous
Dropping the IDS concept is essentially stepping away from a viable and proactive approach to security. This is the same for IPSs. Incident handling is simply reactive. We must automate what we can as much as possible and in a secure manner to properly defend our critical systems in real time. No human can react faster than an automated tool. Attackers will continue to develop technology for circumvention and unless we do the same, we will be left in the dust.

Instead of looking at what technology we need to do away with, we need to be looking at technology that needs to be developed/augmented. The augmentation of the IDS concept to include active response (IPS) proves this as an advancement pattern. Any idea should only fade away in the shadow of a better solution. If Dave can come up with a proactive approach that proves his two cents in ROI as well as proven decrease in security incidents, I'll give him a dollar.

-k

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/457/34804#34804
NSM == IDS++ 2007-11-26
Hanashi
Don't blame the IDS 2009-08-14
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus