IDS Requirements

m2a85_at_unb.ca
Date: 06/15/04

  • Next message: infor) urko zurutuza: "RE: IDS Requirements"
    Date: 15 Jun 2004 12:54:41 -0000
    To: focus-ids@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Hi,
     
    I have begun a research project that focuses on
    determining the essential features IDS Software must
    implement. Primarily I am concerned with features
    that network administrators are either currently
    using extensively in daily operations or hope will
    become available in the future.
     
    I have read many articles referring to current IDS
    systems and their passive approach to securing
    networks from the lateset global threats. Has their
    been any advancements in providing network
    administrators with the ability to impose preemptive
    measures before network breaches occur? What tools
    are being research by industry leaders?
     
    Any links, documents, or lists of core features and
    abilities that an IDS must have would be great.
     
    Thank you for your time, any followups would be
    greatly appreciated.

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: infor) urko zurutuza: "RE: IDS Requirements"

    Relevant Pages

    • Re: IDS and NMS
      ... Start by designing and installing a network. ... Next, a more detailed view of the network is required, so a NMS is ... the network administrator wants to see what ... This is where integrating the IDS console into the NMS makes sense. ...
      (Focus-IDS)
    • Re: "false positive" inanity
      ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
      (Focus-IDS)
    • Re: Secure Network Design (DMZ, LAN, etc)
      ... I'd like one outside the firewall and one ... I assumed I could make the first IDS ... should I have the IDS listening on the 192.168.1.0/24 network as well (web ... >Since the whole world will need access to your web servers, ...
      (Security-Basics)
    • Re: Need some information on HIDS!
      ... I have already invoked such a scenario in some of my previous IDS ... What I had in mind is something like encrypting the whole ... network traffic, to prevent sniffing from intruders (let's say wall-to-wall ... analysing and displaying logs. ...
      (Focus-IDS)
    • Re: which attacks will generate false positive or false negative?
      ... addresses of the servers on your network that are allowed to do DNS Zone ... you first install a Network IDS, snmpwalks may trigger from your network ... Matt brings up the point of alerts to things that didn't have any ... you're not sure of the best way to tune out false positives during your ...
      (Focus-IDS)