Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Enterprise Intrusion Analysis, Part One
Stephen Barish

We all remember the early days of intrusion-detection systems — IDS was supposed to be the silver bullet that ensured the security of our enterprises against every conceivable attack. It was the same premise that the firewall industry and the giant antivirus conglomerates were built around: Buy our product and your worries are over.

Comments Mode:
Enterprise Intrusion Analysis, Part One 2009-06-28
Anonymous (1 replies)
Enterprise Intrusion Analysis, Part One 2009-08-20
Anonymous
This is a good start, but the analysis would have been more useful explaining the varuios deployment options for IDS - Pros and Cons. Lets be real - IDS on the outside only of your network monitoring the Internet is lots of traffic that a majority should not even be looked at. This traffic just burns you out - no matter what level you are. Signatures are signatures, but you still have that human burn rate to deal with.

What is everyone's experience with letting FWs do their thing and looking at the traffic that gets through the first layer of defense only. I struggle with the old school IDS then FW architecture.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1904/1378#1378







 

Privacy Statement
Copyright 2009, SecurityFocus