Re: Recent Gartner IDS/IPS report

From: Andreas Hess (andi_hess_at_web.de)
Date: 06/19/03

  • Next message: Paul Benedek: "RE: Recent anti-NIDS Gartner article"
    Date: Thu, 19 Jun 2003 16:54:55 +0200
    To: focus-ids@securityfocus.com
    
    

    Hi,

    I have just a short question. I can see the benefit of an IPS, namely
    that it is possible to prevent certain attacks.
    But still, an IDP is prone to false positives, in the same was as an IDS
    - or did I miss something?
    The evaluation process whether or not an attack is taking place does not
    differ from what an IDS does. There are no new techniques!
    Certainly, it is possible to combine different analysis technologies and
    perhaps this also pais out but this is not said!

    To my opinion it makes sense to block attacks which can be reliably
    identified, but what about the others?
    The limiting factor is still the rate of false alarms!

    Regards

    Andreas

    -------------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's to
    "underground" security specialists. See for yourself what the buzz is about!
    Early-bird registration ends July 3. This event will sell out. www.blackhat.com
    -------------------------------------------------------------------------------


  • Next message: Paul Benedek: "RE: Recent anti-NIDS Gartner article"

    Relevant Pages

    • Re: Snot/state
      ... but not eliminate false positives by enabling this feature. ... > maintaining what the IDS considers state, ... maybe the ultimate IDS is only going to alert me to things that I ... they handle quite a few attacks - attacks that they are well aware of. ...
      (Focus-IDS)
    • False positives, negatives and dont cares
      ... Just following up the "IDS is dead, etc" thread, I thought I'd lay out ... False positives happen when the IDS ... attacks heading to targets that aren't vulnerable to them. ... that Snort generates "tons of false positives". ...
      (Focus-IDS)
    • RE: "false positive" inanity
      ... are we concerned about IDS ... finding all possible attacks better or do we just care about the attacks ... Using this type of technologies, ... truly cut down false positives without increasing false negatives ...
      (Focus-IDS)
    • RE: Intrusion Prevention
      ... Coverage what can it detect; this covers basic attacks, ... IDS purchase. ... While doing these implementations and while working in an IDS vendor I ... sometimes we're told that we cannot see the testing methodology upfront. ...
      (Focus-IDS)
    • RE: Changes in IDS Companies?
      ... This means you need a standard IDS sitting behind it/next to it watching the ... Things like port scans and DoS attacks ... >>> If people are running insecure web servers, ... > Pretty sad state of affairs, when people don't update their patches at ...
      (Focus-IDS)

    Loading