Re: Managed Security Providers (Who do IDS & Firewall Monitoring and Blocking)

From: Misha (misha@equinox.alluvium.com)
Date: 01/31/02


Date: Wed, 30 Jan 2002 17:02:03 -0600 (CST)
From: Misha <misha@equinox.alluvium.com>
To: Mike Shaw <mshaw@wwisp.com>


> day for every freakin' nimda false positive? If not, how are they going to
> know what a real intrusion attempt is?

Thats one of the key benefits of outsourcing security monitoring. Your
MSSP should be weeding out real alerts from false positives, and be able
to escalate the problem to you according to your security policy. Not
every problem needs to be escalated in real time, and there are ways to
tell whether an IDS alert is a false positive or not without having to
contact someone.

I also do not necessarily believe penetration tests are a good measure of
effectiveness of an MSSP. For a lot of the companies a penetration test
consists of paying someone to run a commercial security scanner, which
readily identify themselves in the scan. Most IDS analysts I know would
simply disregard that as trolling, and would not make it an issue
warranting a wake up call in the middle of the night. Actively
participating in security monitoring and auditing the MSSPs work is much
more useful, although not nearly as flashy.

> For $6000/month you're getting close to being able to hire your own
> competent security engineer depending on where you are. Someone with hands
> on job responsibility and a real stake in the security of your network.

I have worked with companies that had fully staffed security departments,
along with several compromised hosts on the network. No one knew they were
there. I wouldn't say their security people were stupid, they just had
other things to do most of the time.

Having someone on the payroll does not necessarily mean they are competent
to have a real stake in the security of your network. Nor does it mean
that a single security engineer can cover your network 24/7. MSSPs can
offer a way to deal with this, and this has nothing to do with a really
nice looking NSOC.

Misha



Relevant Pages

  • Re: Managed Security Providers (Who do IDS & Firewall Monitoring and Blocking)
    ... What are your thoughts concerning whether or not the MSSP ... network and your business. ... of knowing if the guy at the console is a wonderstud security guru or a ... > its day on X numbers of other customers. ...
    (Focus-IDS)
  • Re: Announcement: Alert Verification for Snort
    ... > an IDS vendor, and I know how much of a glass bubble it can be. ... If only 10 out of 10000 security events in your ... "false positives" that were not really false positives as a different ... and/or the vulnerability profile of devices on the network. ...
    (Focus-IDS)
  • Re: Truth about False Positives
    ... Subject: Truth about False Positives ... >>> Security Administrator, AsiaPac ... >>> false alarms. ... >>> attack was real or not. ...
    (Focus-IDS)
  • RE: False Positives (Definitions White Paper)
    ... False Positives: A user's guide to making sense of IDS alarms ... Robert Graham - Internet Security Systems ... INTRUSION PREVENTION: READY FOR PRIME TIME? ...
    (Focus-IDS)
  • Re: Truth about False Positives
    ... Subject: Truth about False Positives ... >> International Security Group ... >> defining false positives & false alarms, and what steps we are taking to ... >> attack was real or not. ...
    (Focus-IDS)