Focus on IDS
Ideal IDS/IPS Jun 02 2011 03:20AM
snort user (snort user gmail com) (1 replies)
Re: Ideal IDS/IPS Jun 06 2011 06:28AM
Michal Zalewski (lcamtuf coredump cx)
> Low false negatives   - maximize detection and prevention of
> intrusions, detect zero day attacks, detect variations
> Low false positives   - don't waste analyst time
> Ease of use           - installation and configuration
> Low resource usage    - minimize resource usage, degrade gracefully
> when resource usage exceeds limits
> High Performance      - good scalability with increasing network speeds
> Stability, Robustness - no crashes, and resistance to attacks againt IDS
> Minimal ongoing maintainence - Run with minimal human supervision

And a pony!


