Re: IDS evaluation

From: securityguy@hush.com
Date: 08/21/02


Date: 21 Aug 2002 21:30:06 -0000
From: <securityguy@hush.com>
To: focus-ids@securityfocus.com


('binary' encoding is not supported, stored as-is) In-Reply-To: <OFBC4A3F41.A9EE807A-ON85256C1C.006DD317@com>

Depending on the expertise you have in your organization you might want to
look at Snort. I am in the middle of setting up Shadow IDS (also a free
solution) and find Snort to be easier/better.

But if commercial products are what you need, apparently the next version
of ISS RealSecure is supposed to be better -- be warned that RealSecure
takes a lot of tweaking to get to run properly with few 'false alerts'.
Intrusion.Com Secure Net pro is also worth a look -- the product is good
but I don't have a lot of faith in the company as they seem to be a boat
with no direction.

To me, Snort is the best solution and if you have to, you can even pay for
it these days.

>I am coming to you experts for a little help. It has come time to renew
our
>maintenance contract with cisco we have the old netranger product. Well my
>company wants me to do a review of 3 products of my choice to see what
>other products may provide us a better solution that what we currently
>have. We have 12 IDS sensors currently. Can you all recommend 3 products
>that will be worth my time to take a look at?
>
>I would greatly appreciate any answers.
>
>



Relevant Pages

  • Re: on NIDS/NIPS tuning
    ... Hell, we've even Snort users ... That expertise is a fairly esoteric set of skills ... Sourcefire - Network Defense for the Real World - http:// ... Snort: Open Source Intrusion Detection and Prevention - http:// ...
    (Focus-IDS)
  • Re: Snort IDS
    ... I'm a security analyst working in a financial organization. ... At this and previous such I've installed Snort IDS sensors. ... _Any_ IDS deployment requires an appropriate amount of expertise. ...
    (Security-Basics)
  • Re: [SLE] Web administration of home network
    ... > Setting up the initial rule set for the Snort and SnortSam pair can be a bit ... > of a pain. ... The results are well worth it though. ...
    (SuSE)
  • Re: Vulnerability and Penetration Testing?
    ... ZoneAlarm is well worth the money paid for it! ... Perhaps a Windows port of Snort by suffice or is Nessus capable of doing a ... better vulnerability testing? ... Snort is a NIDS, not a penetration tester. ...
    (comp.security.firewalls)
  • Re: OT: car buying
    ... Typo of the week, absolutely. ... especially as it's worth buttons ATM (a ...
    (uk.rec.motorcycles)