ISS Siteprotector as syslog server?

From: Bowes, Ronald (EST) (RBowes_at_gov.mb.ca)
Date: 11/18/04

  • Next message: Julius Detritus: "RE: need your help about IPS and IDS,thanks"
    To: "'focus-ids@securityfocus.com'" <focus-ids@securityfocus.com>
    Date: Thu, 18 Nov 2004 09:08:58 -0600
    
    

    We're trying to get several different systems (ips and ids) to work
    together, as we're evaluating ips products made by various vendors.

    The ips appliances we're using can export their data to a syslog server, and
    it would be nice if we could import the syslog data into ISS SiteProtector.
    Has anybody tried to do that before?

    Thanks,
    Ron Bowes

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Julius Detritus: "RE: need your help about IPS and IDS,thanks"

    Relevant Pages

    • RE: Recent Gartner IDS/IPS report
      ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... combinations that operating systems and applications respond improperly ... IDS alerts / second - Correlation - Virtualization ... any IPS has to do IDS first. ...
      (Focus-IDS)
    • RE: IDS alerts / second - Correlation - Virtualization
      ... If you take a proper IPS, and by that I don't mean an IDS that has been ... followed by rate limiting and Layer 4 checks before it ...
      (Focus-IDS)
    • RE: Intrusion Prevention Systems
      ... It seems were calling an reactive IDS and IPS. ... In reality, BlackICE Guard ... IPS is hardly a "test lab device" or unproven technology. ...
      (Focus-IDS)
    • RE: IDS evaluations procedures
      ... An example would be to use an IPS to force all HTTP requests to have the host header www.xyz.com this will stop a significant proportion of HTTP noise before signature matching. ... Conversely with IDS you just don’t have the ability to white list traffic in this way, I guess you could RST any request that didn’t match the URL but I think fragmented buffer overflows and the like could sneak through - so it’s risky. ... Traffic-based anomalies? ... Are you only interested in classic "attacks" (fire up Nessus, ...
      (Focus-IDS)