Re: MSSP / IDS Selection

From: Mark Teicher (mht3_at_earthlink.net)
Date: 03/16/05

  • Next message: Dave Aitel: "Re: How to choose an IDS/FW MSS provider"
    Date: Wed, 16 Mar 2005 16:40:52 -0500 (GMT-05:00)
    To: KJP <kjp011975@gmail.com>, focus-ids@securityfocus.com
    
    

    Are you looking for opinions regarding outsourcing managed security services versus internally. If your organization brings the managed of security services in house, it is very hard to sue an internal person or internal department for doing something silly, but if you are being monitored by a managed security service who have service level agreements, it is much easier to to sick some lawyerly type people or contract beedy eyed people at them. The bigger issues with MSS/MSP's is quality of service, how much for how little, if you pay this much money, how much do you get in return on reporting, analyzt, provisioning, etc.

    The biggest concern with outsourcing managed security services is you get what you pay for, unless some offer manager tells you different, if they say "plus you got all of this plus a big mean grumbly guy out of NC who will call every once in a while to tell you someone is rattling your network door knobs", it might not be so bad then :)

    -----Original Message-----
    From: KJP <kjp011975@gmail.com>
    Sent: Mar 13, 2005 5:51 PM
    To: focus-ids@securityfocus.com
    Subject: MSSP / IDS Selection

    I have spent much time researching various MSSP's NetSec, Verisign,
    Counterpane, and LURHQ for my company. After much research we decided
    to go with Verisign for numerous reasons. After selecting Verisign we
    began narrowing down pricing. On a monthly level the pricing looks
    ok, until you look at it at a yearly level the pricing starts to get
    scary.

    We looked into doing the same service internally using Snort. I
    remembered the comercial implentation of Sourcefire and began
    researching it. It appears to offer services that Snort does not, RNA
    and Defense Center offer the pieces missing from Snort, plus it
    packages the support so I don't need to worry about hardware support,
    OS support, etc.

    What are the opinions of Snort and Sourcefire versus ISS, Cisco,
    Enterasys, Symantec?

    Thanks in advance.

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Dave Aitel: "Re: How to choose an IDS/FW MSS provider"

    Relevant Pages

    • MSSP / IDS Selection
      ... I have spent much time researching various MSSP's NetSec, Verisign, ... We looked into doing the same service internally using Snort. ... packages the support so I don't need to worry about hardware support, ...
      (Focus-IDS)
    • Re: Value of "richer" signatures?
      ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
      (Focus-IDS)
    • Re: ids inquisition
      ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
      (Focus-IDS)
    • RE: IDS recommendations
      ... Subject: IDS recommendations ... Snort is a relatively raw tool and that usually adds ... >> I can appreciate your comments on the ISS product. ...
      (Focus-IDS)
    • RE: "Free" IDS
      ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
      (Focus-IDS)

  • Quantcast