Re: session logging IDS

From: Stefan Keller (stefan.keller_at_gmail.com)
Date: 09/01/04

  • Next message: faisal99_at_inf.its-sby.edu: "question about anomalies detection"
    Date: Wed, 1 Sep 2004 10:50:51 +0200
    To: Raj Malhotra <ral.mal@gmail.com>, focus-ids@securityfocus.com
    
    

    Hi,

    for high-level session overview information older software like ARGUS
    would work, too.
    As for the size of the hard drive, that would depend on the volume of
    traffic that is actually monitored and the frequency of the reviews.
    If you rotate logs and automatically delete the old ones...
    All in all, the "log all" approach seems very ambitious, esp. as IDS
    has a reputation as a dust-collector in many companies. - Will you
    have staff monitoring the IDS 24/7? With periodic reporting from them?

    Regards

    Stefan


  • Next message: faisal99_at_inf.its-sby.edu: "question about anomalies detection"