RE: Low cost HID based IDS system

From: Schmehl, Paul L (pauls_at_utdallas.edu)
Date: 05/17/03

  • Next message: barak_israel_at_hotmail.com: "ISS Network Sensor Compatible Appliance"
    Date: Fri, 16 May 2003 23:10:15 -0500
    To: "Alan Shimel" <alan@latis.com>, "Zach Forsyth" <Zach.Forsyth@kiandra.com>, "Focus-Ids" <focus-ids@securityfocus.com>
    

    Nothing in life is free. Everything has a cost associated with it. For
    example, while he may be able to provide a similar service for much less
    money, what happens if he misses an attack that devastates one of his
    customer's networks? Will he indemnify them? Will they sue him and
    destroy *his* business in the process? Is he going to be watching the
    IDS 24/7 like an MSSP would? Is he knowledgeable enough of IDS to
    provide the same level of service to them that an MSSP would? Does he
    have the resources?

    Everything has a cost. Sometimes the cost doesn't show up until you've
    already realized the decision you made was flawed. What's the value of
    the business lost while your network is down?

    I just don't think it makes good business sense to cut corners on
    security to save a few dollars. In the end, you'll regret it. ISTM he
    would serve his customers better by negotiating a reasonable rate for
    the services of an MSSP *through* his company to each of his customers.
    With his higher bargaining power, he has the opportunity to provide them
    with real value at a reasonable cost that is much less than what they
    might be able to negotiate on their own. Especially now, when security
    companies are scrambling to find revenue.

    In the final analysis the question he needs to answer is; is he trying
    to provide his customers with true value for their dollars? Or just
    throw together something cheap that will make them feel safer but won't
    really make them any more secure?

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu/~pauls/

    -----Original Message-----
    From: Alan Shimel [mailto:alan@latis.com]
    Sent: Friday, May 16, 2003 10:00 PM
    To: Schmehl, Paul L; Zach Forsyth; Focus-Ids
    Subject: RE: Low cost HID based IDS system

    There are tools out there that would allow him to provide these services
    to customers at substantially below some of the MSSPs you mentioned
    charged. I think it is possible to provide this service sub-1000
    dollars a month

    -------------------------------------------------------------------------------
    INTRUSION PREVENTION: READY FOR PRIME TIME?

    IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities
    - including intrusion identification, relevancy, direction, impact and analysis
    - enabling a path to prevention.

    Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at:
    http://www.securityfocus.com/IntruVert-focus-ids2
    -------------------------------------------------------------------------------


  • Next message: barak_israel_at_hotmail.com: "ISS Network Sensor Compatible Appliance"

    Relevant Pages

    • Re: LW "hobbyist pricing"
      ... The $0 one is just to generate goodwill, build market awareness, and allow potential customers to ... sales of the professional edition, but my guess is that leaving out the application delivery from the hobbyist edition is what would draw people who need it to the professional edition. ... Also, it would help if you could convincingly argue that these new customers would be likely to pay for support (i.e. become an ongoing revenue stream, rather than the more likely group that doesn't pay for maintenance, complains in public about the cost and timing of upgrades etcetera). ...
      (comp.lang.lisp)
    • Re: Cingular dropping more customers that they sold service to, due to 50% policy
      ... ARPU (averager revenue per user). ... customers" as one of its advantages in the Japanese market. ... I'm looking at a two year cost ... subscriber cost analysis over the last three years. ...
      (alt.cellular.cingular)
    • Re: Newbie 0870 questions
      ... and usually have no cost unless you ... >> even higher rate than landline calls. ... Thank you Peter & others for your replies. ... I have been trading for 15 years & never advertise, any new customers are ...
      (uk.telecom)
    • Re: Lets think who will like to say delphi is dying?
      ... When it is a mjor investment in R&D, you bet the cost side is going ... As far as Object Pascal is concerned, all the versions since Delphi 3 ... Of course one has to keep eye on the market --and try to run as fast as ... sell directly to the customers --and, ...
      (borland.public.delphi.non-technical)
    • Re: Sears bails on NASCAR
      ... derived from signature sponsorship. ... Writing off $11 million in advertising costs may mean a "true" ... The cost has to be looked at ... in terms of the number of potential customers who will see ...
      (rec.autos.sport.nascar.moderated)

  • Quantcast