Re: IPS, alternative solutions

From: Jason (security_at_brvenik.com)
Date: 09/15/04

  • Next message: Alex Butcher, ISC/ISYS: "Re: IPS, alternative solutions"
    Date: Wed, 15 Sep 2004 15:47:28 -0400
    To: Scott Wimer <scottw@cylant.com>
    
    

    I've heard of no medium+ sized business that is considering deploying
    inline technology on the internals of the network in a sufficiently
    pervasive manner that there would be any measurable benefit from the
    technology over patching and asset management.

    I would be seriously interested in an ROI that can demonstrate savings.

    The simple question is how is inline packet scrubbing easier and more
    cost effective than patching?

    Scott Wimer wrote:

    > Daniel,
    >
    > I agree with your assessment. What I have encountered in the
    > financial sector though is a desire to have the packets "scrubbed"
    > before they reach the servers. People _want_ to deploy network based
    > IPS tools because it is easier and more cost effective. That it
    > doesn't seem to be possible yet is another story altogether.
    >
    > Regards, Scott Wimer
    >
    > On Tue, 2004-09-14 at 06:01, Daniel wrote:
    >
    >> So far there has been a load of talk discussing which is the better
    >> technology. Personally i dont think IPS is ready for the big time.
    >> Yeah its great for small mum and dad networks, but for large
    >> financial networks with billions of pounds flowing across them,
    >> would you trust a technology to think and block what it seems as
    >> bad traffic?
    >>
    >> So what are the alternatives? I'd say more host based protection
    >> such as:
    >>
    >> - Stack protection - Application level firewalls
    >> (ModSecurity/SecureIIS) - Host based firewalls
    >>
    >> I'm interested to see what everyone else feels are alternatives to
    >> IPS
    >>
    >>
    >> --------------------------------------------------------------------------
    >> Test Your IDS
    >>
    >> Is your IDS deployed correctly? Find out quickly and easily by
    >> testing it with real-world attacks from CORE IMPACT. Go to
    >> http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    >> to learn more.
    >> --------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
    --------------------------------------------------------------------------


  • Next message: Alex Butcher, ISC/ISYS: "Re: IPS, alternative solutions"

    Relevant Pages

    • Mesh Networks: New Options for Wireless Users
      ... The race has begun to make wireless networks more viable for cities, ... environments where the technology used in today's Wi-Fi hotspots might ... Mesh Backbone ...
      (comp.dcom.telecom)
    • Re: How to get into Scientific Programming
      ... >> new principle or process. ... >mainly about technology, how technological knowledge accumulates, and ... That's what happened with the networks you see today. ... Compuserve sold access back then. ...
      (comp.programming)
    • Wireless Carriers Create 4G Initiative
      ... technology evolution beyond 3G." ... which calls itself the Next Generation Mobile Networks ... Initiative and which formally incorporated in the U.K. as NGMN ...
      (alt.internet.wireless)
    • Re: Evidence for Big Leaps?
      ... The biochemical networks and the networks of neurons ... networks even bother to create the mutations to produce nervous ... Therefore, after the multi-cellular technology was developed, ... networks in molecular level engineering of the new cells. ...
      (talk.origins)
    • New Possibilities Using Trainable Digital Logic
      ... I thought I would share this informaton with the group and start a new ... networks and the applications in electronic design. ... Another example is the recognition of handwriting; ... the technology is still primitive. ...
      (sci.electronics.design)