RE: IDS Testing

From: agetchel@kde.state.ky.us
Date: 10/25/01


Message-ID: <31860BB65652D31182E7002035221E1A09B520DD@kdemailn1.kde.state.ky.us>
From: agetchel@kde.state.ky.us
To: mikeybarrimore@hotmail.com
Subject: RE: IDS Testing 
Date: Thu, 25 Oct 2001 17:05:20 -0400

Hi Mike,

A good (yet sometimes expensive) solution to this problem is to have a
company or private consultant come in an do an audit or pen test of your
network (including your IDS) to see exactly where your weaknesses are.
Think of it this way... if you've overlooked something when you were
implementing your security infrastructure, chances are you're going to
overlook it when testing it as well. Under these circumstances, I find it
best to leave it to the guys who do this stuff for a living.

It also pulls a lot more weight with management when you can say 'Company
XYZ has performed a pen test against our network and found these issues we
need to address' rather than 'I downloaded this app from the Internet and
ran it'.

Thanks,
Abe

PS-In no way am I affiliated with any penetration testing firms. =)

Abe L. Getchell - Security Engineer
Division of System Support Services
Kentucky Department of Education
Voice 502-564-2020 ext. 225
E-mail agetchel@kde.state.ky.us
Web http://www.kde.state.ky.us/

> -----Original Message-----
> From: Mike Barrimore [mailto:mikeybarrimore@hotmail.com]
> Sent: Thursday, October 25, 2001 4:17 PM
> To: focus-ids@securityfocus.com
> Subject: IDS Testing
>
>
> Hi,
>
> I have been running network ids for a while now and I keep
> getting asked the
> question by my boss, more recently after the 11th Sept, how
> do you know that
> it is working as it should be. Other than downloading all of
> the attacks and
> running them I'm not really sure.
>
> Is there any easy to run apps that anyone can recommend? I
> just need to
> prove that it is doing what we think it is doing.
>
> Mikey
>
> _________________________________________________________________
> Get your FREE download of MSN Explorer at
http://explorer.msn.com/intl.asp



Relevant Pages

  • RE: IDS Testing
    ... Subject: IDS Testing ... >> find Shadow Security Scanner let me know and I'll send it to you. ... >> I have been running network ids for a while now and I keep getting asked ... Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp ...
    (Focus-IDS)
  • IDS Testing
    ... Subject: IDS Testing ... I have been running network ids for a while now and I keep getting asked the ... question by my boss, more recently after the 11th Sept, how do you know that ... Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp ...
    (Focus-IDS)