RE: IDS



This is not the function of IDS. It can only display
you alerts for the malicious traffic that pass through
IDS. You better think about some VA tool like
Nessus/GFI/ISS/Foundscan etc.

You can even explore some Vulnerability Management
tool that would be lil automated and administrator
need not to scan the network manually everytime. I
have never tried this product, so don't know how
effective is that.

But yes, If you want to enforce security policies and
complance to patches for the remote users entering
your network via VPN, then you can explore
CybergateKeeper
[http://www.infoexpress.com/security_products/remote_access_overview.php]

Cheers,
Dhruv


-----Original Message-----
From: Gopinath_Ramamoorthy@xxxxxxxxxx
[mailto:Gopinath_Ramamoorthy@xxxxxxxxxx]
Sent: Monday, July 03, 2006 12:58 AM
To: focus-ids@xxxxxxxxxxxxxxxxx
Subject: IDS

Dear Team...

I have used few IDS in my network, doesn't found
them working in the way
i wanted.
My requirement is when there is a machine / laptop
are connected to my
network, which is not updated with the current
Patches, Security updates
which is being approved needs to be reported to the
Sys admin and
immediate necessary steps would be taken.
Is it possible to have this & if so suggest me the
options pls.

Regards,
Gopi


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with
real-world attacks from
CORE IMPACT.
Go to

http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.

------------------------------------------------------------------------


This e-mail and any documents transmitted with it
are the property of SOUTHBank F.S.B. ® and/or its
subsidiary or affiliate companies, is confidential,
and intended solely for the use of the individual or
entity the e-mail is addressed to. If you have
reason
to believe that you have received this message in
error, please notify the sender and delete this
message immediately from your computer. Any other
use, retention, dissemination, forwarding, printing,
or copying of this e-mail or attachments is strictly
prohibited.

SOUTHBank, F.S.B. and/or its subsidiary or affiliate
companies do not endorse the use of unsolicited
e-mail. If you believe this e-mail was sent to you
in error or you do not wish to receive these types
of e-mail, please notify us by forwarding this
message to remove@xxxxxxxxxxxxxx



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to

http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.

------------------------------------------------------------------------




__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: anomaly IDS ideas ?
    ... algorithm which tries to find outliers on network traffic. ... should issue an alert if the host opens a port which wasnt open before ... Test Your IDS ... with real-world attacks from CORE IMPACT. ...
    (Focus-IDS)
  • Re: IDS and NMS
    ... Start by designing and installing a network. ... Next, a more detailed view of the network is required, so a NMS is ... the network administrator wants to see what ... This is where integrating the IDS console into the NMS makes sense. ...
    (Focus-IDS)
  • Re: "false positive" inanity
    ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
    (Focus-IDS)
  • Re: Secure Network Design (DMZ, LAN, etc)
    ... I'd like one outside the firewall and one ... I assumed I could make the first IDS ... should I have the IDS listening on the 192.168.1.0/24 network as well (web ... >Since the whole world will need access to your web servers, ...
    (Security-Basics)
  • Re: which attacks will generate false positive or false negative?
    ... addresses of the servers on your network that are allowed to do DNS Zone ... you first install a Network IDS, snmpwalks may trigger from your network ... Matt brings up the point of alerts to things that didn't have any ... you're not sure of the best way to tune out false positives during your ...
    (Focus-IDS)