Current IDS problems

From: zero (zeroboy_at_arrakis.es)
Date: 10/19/05

  • Next message: Teemu Schaabl: "Re: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor"
    Date: Wed, 19 Oct 2005 00:14:55 +0200
    To: focus-ids@securityfocus.com
    
    

    Hi all,
       I would like to know what are the problems people working with IDS sees in
       them. I mean, what are the things you hate about IDS, think simply you feel
       are plain wrong or that they should be another way to it.

       Al comments are greatly appreciated :)

       Thxs in advance.

       

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Teemu Schaabl: "Re: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor"

    Relevant Pages

    • Re: RE: IDS testing tools
      ... Nessus is a bad choice to test IDS as it is a vulnerability scanner. ... >Find out quickly and easily by testing it with real-world attacks from CORE ... >with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • Re: Host Based IDS
      ... Assunto: RE: Host Based IDS ... Anitian Enterprise Security ... with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • RE: IDS
      ... Subject: IDS ... Safe Access that does pretty much what you describe. ... Find out quickly and easily by testing it with real-world attacks from ... with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • RE: IDS event filtering
      ... It is important to avoid tuning out real attacks when they happen by having over-pruned the inside attack tree... ... > ingress - egress firewall rules, IDS configs, or whatever. ... > CORE IMPACT. ... > Find out quickly and easily by testing it with real-world attacks from ...
      (Focus-IDS)
    • RE: Fortinet IDS
      ... Their list of spyware and adware is limited, ... I believe they used Snort for their IDS. ... Find out quickly and easily by testing it with real-world attacks from CORE ... Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)