Re: Changes in IDS Companies?

From: Eye Dius (nthlayer@yahoo.com)
Date: 10/17/02


Date: 17 Oct 2002 07:26:25 -0000
From: Eye Dius <nthlayer@yahoo.com>
To: focus-ids@securityfocus.com


('binary' encoding is not supported, stored as-is) In-Reply-To: <003101c27594$5de8e970$01000001@SecurityConscious.com>

- snip -

>IDS vendors have not
>been able to get false alarm/postive rates down to a level where
>organizations would trust an IDS alert to enforce network policy.
>
>Nothing I've seen or read from these new vendors gives me any reason to
>believe they have cured the cancer of IDS - false alarms/positives.

What are some of the big reasons for false positives? What is preventing
new or existing vendors from fixing this problem?



Relevant Pages

  • RE: Recent Gartner IDS/IPS report
    ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
    (Focus-IDS)
  • Re: On IDS Evasion, Vulnerabilities, and Vendor Hype
    ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... encoding, unlike %u encoding." ... How long was it before some vendors ... > vulnerability. ...
    (Focus-IDS)
  • On IDS Evasion, Vulnerabilities, and Vendor Hype
    ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... IDS vendors sometimes must completely rewrite parts of their engines ... Eeye cast the first stone with their advisory %u encoding IDS bypass ... vulnerability. ...
    (Focus-IDS)
  • On IDS Evasion, Vulnerabilities, and Vendor Hype
    ... On IDS Evasion, Vulnerabilities, and Vendor Hype ... IDS vendors sometimes must completely rewrite parts of their engines ... Eeye cast the first stone with their advisory %u encoding IDS bypass ... vulnerability. ...
    (Bugtraq)
  • RE: Intrusion Prevention
    ... but the same is true for all commecrcial vendors ... >sometimes we're told that we cannot see the testing methodology upfront. ... >This dumbfounds me for all the reasons that MJR already ... IDS testing is too easy to inadvertently (and sometimes ...
    (Focus-IDS)