Re: Current IDS problems

From: Terry Vernon (tvernon24_at_comcast.net)
Date: 10/22/05

  • Next message: Nakul Aggarwal: "Re: Current IDS problems"
    Date: Sat, 22 Oct 2005 04:12:30 -0500
    To: crazy frog crazy frog <i.m.crazy.frog@gmail.com>
    
    

    False positives is one, the algorythms used to scan traffic is another,
    un-flexibility is another big one.

    Most of these problems are easily solved except for when you make a
    commercial product you have to "dumb it down" so the end users can
    handle it. I'm designing an IPS for a large customer whom we all know
    and you would figure these people should know it all. I have to put
    miles of if statements in the code with accompanying error messages to
    describe why you cant do this or that. When we can open up the throttle
    and not worry about the end user we can have some awesome stuff on the
    market. Take "vi" the text editor for example. To a newb it's terrible
    but to someone who's used to it it's a necessity. Most of the truly
    useful features in these products wind up on the cutting room floor
    because the decision makers don't want to do it for money or time
    constraints. To tell you the truth your better stuff is coming from
    smaller companies and not symantec, cisco, etc... Anyone who begs to
    differ works for one of the said companies. The executives keep tight
    leashes on the development departments.

    Terry Vernon
    CTO/Senior Developer
    Sprite Technologies

    crazy frog crazy frog wrote:

    >false positives.allthough we need to fine tune it to reduce this stuff.
    >
    >On 10/19/05, zero <zeroboy@arrakis.es> wrote:
    >
    >
    >>Hi all,
    >> I would like to know what are the problems people working with IDS sees in
    >> them. I mean, what are the things you hate about IDS, think simply you feel
    >> are plain wrong or that they should be another way to it.
    >>
    >> Al comments are greatly appreciated :)
    >>
    >> Thxs in advance.
    >>
    >>
    >>
    >>
    >>------------------------------------------------------------------------
    >>Test Your IDS
    >>
    >>Is your IDS deployed correctly?
    >>Find out quickly and easily by testing it
    >>with real-world attacks from CORE IMPACT.
    >>Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    >>to learn more.
    >>------------------------------------------------------------------------
    >>
    >>
    >>
    >>
    >
    >
    >--
    >ting ding ting ding ting ding
    >ting ding ting ding ding
    >i m crazy frog :)
    >
    >------------------------------------------------------------------------
    >Test Your IDS
    >
    >Is your IDS deployed correctly?
    >Find out quickly and easily by testing it
    >with real-world attacks from CORE IMPACT.
    >Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    >to learn more.
    >------------------------------------------------------------------------
    >
    >
    >
    >

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Nakul Aggarwal: "Re: Current IDS problems"

    Relevant Pages

    • RE: Current IDS problems
      ... We're actually working an IPS here. ... >>with real-world attacks from CORE IMPACT. ... >ting ding ting ding ting ding ...
      (Focus-IDS)
    • RE: Old @Stake Tools
      ... Network Data Security Analyst ... On Behalf Of crazy frog crazy frog ... Cenzic Hailstorm finds vulnerabilities fast. ... ting ding ting ding ting ding ...
      (Pen-Test)
    • [Full-disclosure] Re: sugget a small pentest distro
      ... crazy frog crazy frog wrote: ... >ting ding ting ding ting ding ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Full-Disclosure)
    • Re: [Full-disclosure] IM Sniffer release
      ... Am 28.09.2006 um 19:46 schrieb crazy frog crazy frog: ... ting ding ting ding ting ding ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
      (Full-Disclosure)
    • Re: Current IDS problems
      ... doesn't the existing correlation tools solve the problem of false alerts:-? ... > ting ding ting ding ting ding ... Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)