RE: Questions about filtering

From: McCammon, Keith (Keith.McCammon@eadvancemed.com)
Date: 07/15/02


Date: Mon, 15 Jul 2002 09:34:21 -0400
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: "idslist" <ids@packetstorm.org>, <focus-ids@securityfocus.com>


> Am I asking for too much?

Nope. An IDS that can't be tuned to reduce noise is useless.

> Am I going about this the wrong way? If so is there a better method?

I've never used NFR, and I hope to keep it that way, so I'm of no use if you're looking for technical direction. However, I can tell you that passing on the traffic will be ten times more useful than muddying your screen with a generic "ignore me, I'm false" message. Plus, some systems were designed such that pass rules are processed first, keeping overhead to a minimum in these types of cases.

Having said this, I would urge you to look at Snort before you make a decision. These types if things are easy to clean up using Snort's language, there are more sigs, and performance is comparable (if not superior) to any commercial system that I've used. And it's free!

Cheers

Keith



Relevant Pages

  • Re: [Full-Disclosure] Is Marty Lying?
    ... "if you can set an IDS signature for something, ... Useless." ... I don't know what kind of company you do security for, ... you when you've been compromised by six-month old public vulnerabilities ...
    (Full-Disclosure)
  • Re: Print resolution (was: Where are the BEST Point and Shoot Photos?)
    ... viewing conditions and at normal viewing distance of 22" needs only 156 ... [snipped a lot of totally useless information that would only waste bandwidth ... Your resolution doesn't mean one damn thing if there's nothing in it worth ... Imagine all that noise of SETI. ...
    (rec.photo.digital)
  • Re: Canon S3 IS vs. Panasonic Lumix DMC-FZ7?
    ... That photo is useless, while canon one ... indeed have plenty of noise, but it can be in great deal removed ...
    (rec.photo.digital)
  • Re: Wireless AM analog internet connections?
    ... Than it would be useless ... broadcast frequencies at microwave frequencies. ... hits) is so much higher than the receiver front end noise level. ... amplifying is atmospheric noise. ...
    (alt.internet.wireless)
  • Re: Know your neighbours (USA style)
    ... would show neighbours who create a large amount of noise at the ... time one wishes to sleep - but such a site would be useless since ...
    (uk.legal)

Quantcast