on NIDS/NIPS tuning

From: Anton A. Chuvakin (anton_at_chuvakin.org)
Date: 06/09/05

  • Next message: Joshua Berry: "RE: on NIDS/NIPS tuning"
    Date: Thu, 9 Jun 2005 13:01:20 -0400 (EDT)
    To: focus-ids@securityfocus.com
    
    

    All,

    I was thinking about some issues with IDS alerts (their volume, etc) and
    realized I could use some help from the list. It might also be a fun
    discussion item.

    So, here it is: how many folks who buy/download a NIDS/NIPS actually tune
    it? Long time ago when I was asking this question the previous time, I was
    scared to learn that lots of people do not tune their NIDSs. Is it any
    better now?

    Best,

    -- 
    Anton A. Chuvakin, Ph.D., GCIA, GCIH, GCFA
         http://www.info-secure.org
       http://www.securitywarrior.com
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Joshua Berry: "RE: on NIDS/NIPS tuning"

    Relevant Pages

    • RE: on NIDS/NIPS tuning
      ... I'd suggest that IDStuning is still essential. ... Where to tune is a very good question and not easily answered. ... try to tune on the sensor first and on the SIM second. ... If you tune what appears to be noise at the IDS, ...
      (Focus-IDS)
    • RE: on NIDS/NIPS tuning
      ... But when the SIM tool is thrown into the mix, ... the question becomes where to tune. ... If you tune what appears to be noise at the IDS, ... tuning out known FP's at the IDS should create a higher ...
      (Focus-IDS)
    • Re: on NIDS/NIPS tuning
      ... We certainly *do* tune our IDS devices (whether IDS/IPS of the network, ... IDS tuning. ... Security Intelligence Analyst ...
      (Focus-IDS)
    • Re: on NIDS/NIPS tuning
      ... I know that, in my experience, many orgs don't tune at all. ... I tune sigs and also tailor the sig sets to the devices being ... If I am alerted to an event by an IDS, ... a filter should result, ...
      (Focus-IDS)
    • RE: on NIDS/NIPS tuning
      ... I'm seeing many organizations now tuning not on the IDS, ... product they're using for monitoring them. ... I was scared to learn that lots of people do not tune their ...
      (Focus-IDS)