Re: Value of IDS, ROI

From: Bob Huber (roberthuberjr_at_yahoo.com)
Date: 05/04/05

  • Next message: Vladimir Vuksan: "Re: Value of IDS, ROI"
    Date: Tue, 3 May 2005 17:30:38 -0700 (PDT)
    To: focus-ids@securityfocus.com
    
    

    The easiest approach would be to quantify the cost of
    any worm outbreaks, outages, or compromises you have
    already had if you have the data handy, or guesstimate
    what the cost of an outage of one of your information
    assets would be.

    The second thing that is compelling is the fact that
    most large companies, depending on their industry,
    have legal requirements to have some form of IDS. For
    example, healthcare, insurance have HIPAA, financial
    institutions have Graham-Leach-Bliley, FDIC, SEC, OCC,
    Sarbanes Oxley etc.. Some of these regulations levy a
    fine for lack of controls.

    As far as a monitoring strategy, that all depends on
    the level of risk you are willing to accept and the
    value of your assets/information. Are you processing
    customer data, social security numbers, credit card
    numbers, bank accounts, or just hosting a static web
    site? There are a million factors here to contend
    with, pick up your nearest CISSP cram book.

    Supposing you have something worth protecting, at a
    minimum, you should at least look for signs of a
    compromise, rather than scans, sweeps and information
    probes. While looking at probes, and reconnaissance
    is fun for an IDS geek, if you don't have time, and no
    dedicated security staff, just worry about the heavy
    hitter events and log everything else so when you DO
    have a compromise you at least have the data available
    for review.

    This is a quick and simplistic view..I'm certain there
    are all sorts of articles on the web on such topics,
    as well as books.

    Bob
    --- Jason Patel <patel1210@yahoo.com> wrote:
    >
    >
    > I was wondering how big companies CIO show their
    > executives Return of investment on IDS. What is the
    > monitoring strategy for IDS alerts. I am trying to
    > figure monitoring strategy and how to show my
    > executive that how important job this is, but cant
    > come up with a convincing solution. Anyhelp is
    > highly appreciated.
    >
    > Thanks,
    >
    > Jason

    __________________________________________________
    Do You Yahoo!?
    Tired of spam? Yahoo! Mail has the best spam protection around
    http://mail.yahoo.com

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Vladimir Vuksan: "Re: Value of IDS, ROI"

    Relevant Pages

    • Re: [Full-Disclosure] Is Marty Lying?
      ... > enough to buy the hype of signature-based IDS and to think products like ... The compromise must definately have been limited to ... > their network so if it gets compromised, ... > Snort/Sourcefire network's security. ...
      (Full-Disclosure)
    • RE: "Free" IDS
      ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
      (Focus-IDS)
    • Re: Wednesday, bloody Wednesday ..
      ... IDS can actually lose market share? ... there's a lot of people trying to make 'freebie' or lower cost ... Now what happens if that growth rate could be 50% or higher? ... But there are a lot of DB2 LUW customers who would be exceptionally pissed off at that strategy. ...
      (comp.databases.informix)
    • Re: "Free" IDS
      ... Sometimes in this respect commercial tools reduce the cost of ownership ... But IDS is never free, ... Running Snort in an enterprise is hardly "free". ...
      (Focus-IDS)
    • Re: frontpage extensions; backdoor or initial compromise?
      ... inspection of the machine and additional examination of IDS logs, ... appears that the frontpage extensions were probably just a backdoor. ... The initial compromise vector was most likely the nsiislog.dll ...
      (Incidents)