Mcafee Intrusheild & Entercept performance & detection capabilities

From: Mustapha Huneyd (mhbengal_at_yahoo.com)
Date: 09/06/04

  • Next message: Jose Maria Lopez: "Re: question about anomalies detection"
    To: <focus-ids@securityfocus.com>
    Date: Mon, 6 Sep 2004 09:40:42 +0400
    
    

    Has anyone on the forum, extensively deployed the Mcafee IPS line of
    > products. How is the performance as far as throughput and
    signature/anomaly
    > detection as compared to other top products like the ISS Proventia series
    > and the Cisco IDS (4200 series). Mcafee claim that their behavior and
    > anomaly detection engines are best of the breed. I would love to know how
    > admins who have deployed it feel about the product line.
    >
    > regards
    > Mustapha
    >
    > MUSTAPHA HUNEYD, CISSP
    > Emirates Telecommunications Corporation
    > Mob:+971506625859 Tel: +97126184804
    >

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
    --------------------------------------------------------------------------


  • Next message: Jose Maria Lopez: "Re: question about anomalies detection"

    Relevant Pages

    • RE: Changes in IDS Companies?
      ... It does intrusion detection with alerting and pattern matching ... IDS is down...but at least your network isn't, ... ::: mode being rolled into Snort) are both good technologies ...
      (Focus-IDS)
    • RE: Specification-based Anomaly Detection
      ... Hi Stefano & Toby, ... I feel that the mind set of the discussion was about such applications, ... would not be much different than a network IDS. ... Does this make intrusion detection in web applications deferent? ...
      (Focus-IDS)
    • Re: Alarming (was protocol analysis)
      ... Obviously, there are different ways to "detect" attacks, but John uses the ... no one should ever "rely" on any IDS for our ... As for Johns Metaphor of the motion sensor vs the pressure sensor, ... toward Intrusion Prevention as opposed to just Intrusion Detection. ...
      (Focus-IDS)
    • IDS Assessment (was: Intrusion Prevention... probably something else at one point)
      ... scrutiny of all IDS features/technologies. ... Anomaly-type detection engines can ... weaknesses of each detection methodology (which is described in much ... attack d'jour with a cool sounding name and/or press ...
      (Focus-IDS)
    • RE: Hi, I want to study IPS
      ... >>of systems to pull everything together into an IDS solution. ... you are right that some IPS products use similar techniques as ... technologies in attack detection. ... capabilities, and so have less false positives, which is not true. ...
      (Focus-IDS)