RE: Network IDS

From: Steffen Kluge (kluge_at_fujitsu.com.au)
Date: 08/22/03

  • Next message: Arian J. Evans: "Towards a sound IDS Value Methodology--was-->Gartner is Dead, nCircle, Fusion, asset-correlation..."
    To: focus-ids@securityfocus.com
    Date: Fri, 22 Aug 2003 12:04:20 +1000
    
    
    

    On Wed, 2003-08-20 at 05:52, Robert.Lupo@nokia.com wrote:
    > I have seen time and time again people buying a product, getting
    > vendor training and then viewing the logs and thinking "wo ho! I have
    > IDS!" but do you know how to write your own rules, signatures, analyze
    > the traffic for what your company needs?

    If they don't then that "woohoo!" will quickly turn into a "curse that
    wretched IDS!". The system will swamp them with logs, the sheer amount
    of which will make it near impossible to spot the interesting bits among
    the noise. In the end they will concede that the whole IDS idea was an
    expensive flop.

    I believe this is part of the sentiment the Gartner article reflects.

    Of course, commercial NIDS vendors have only themselves to blame for
    this backlash. While they were busy grabbing a slice of the market the
    new IDS buzzword created they neglected (or forgot, or avoided) to tell
    customers that IDS is a tool that's only useful in skilled hands.

    Cheers
    Steffen.

    
    



  • Next message: Arian J. Evans: "Towards a sound IDS Value Methodology--was-->Gartner is Dead, nCircle, Fusion, asset-correlation..."

    Relevant Pages

    • Processing time and IDS traffic
      ... (forensics, anti-virus, IDS, firewalls, etc.) ... What I did was parse the logs into XML records and arranged them into a nice ... strategically placed IDS system and what people get from a IDS system ... - Automatically Control P2P, IM and Spam Traffic ...
      (Focus-IDS)
    • Re: Random IDS Thoughts [WAS: Re: IDS thoughts]
      ... to allow one to use a SQL syntax to select which logs to convert, ... Subject: Random IDS Thoughts ... IntruShield now offers unprecedented Intrusion IntelligenceTM ... Download the latest white paper "Intrusion Prevention: ...
      (Focus-IDS)
    • Re: Random IDS Thoughts [WAS: Re: IDS thoughts]
      ... Commodotization of the IDS space, in general: ... by flooding a network with "anomalous" traffic so it eventually gets ... I understand that analysing logs take ... Lousy interface design: Most IDS products or log analyzer products I've ...
      (Focus-IDS)
    • RE: Value of IDS, ROI
      ... Adding to Bob's second paragraph - these regulations, require you to monitor ... your audit logs for incidents - we know how long it used to take for one ... person to review a basic audit log with thousands of entries every hour. ... IDS 1-2 people to review logs ...
      (Focus-IDS)
    • Need help to choose a security policy
      ... I have been asked to decrease the amount of IDS logs we get: useless events, ... One of our IDS is located in front of the Internet and the others one are in a private WAN. ...
      (Focus-IDS)