Article Announcement: Checklist for Deploying an IDS

From: Marc Fossi (mfossi_at_securityfocus.com)
Date: 12/30/03

  • Next message: dwr3ck_at_hushmail.com: "Disabling Cached Logon Credentials"
    Date: Tue, 30 Dec 2003 09:43:23 -0700 (MST)
    To: Focus-MS <focus-ms@securityfocus.com>
    
    

    Checklist for Deploying an IDS
    By Andy Cuff Dec 30, 2003

    The scope of this article considers the worst case scenario, that of
    deploying a Network IDS on a remote network (target). The introduction of
    an IDS into a organization's network can be sensitive and often has
    political implications with the network staff, and thus a checklist
    written from the perspective of an outside consultant (even if the IDS is
    deployed internally) that appeases all parties can be useful to ensure a
    successful implementation.

    http://www.securityfocus.com/infocus/1754

    Marc Fossi
    Symantec Corp.
    www.symantec.com

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: dwr3ck_at_hushmail.com: "Disabling Cached Logon Credentials"

    Relevant Pages

    • SecurityFocus new article announcement
      ... Checklist for Deploying an IDS ... The scope of this article considers the worst case scenario, ... deploying a Network IDS on a remote network. ...
      (Security-Basics)
    • Re: IDS and NMS
      ... Start by designing and installing a network. ... Next, a more detailed view of the network is required, so a NMS is ... the network administrator wants to see what ... This is where integrating the IDS console into the NMS makes sense. ...
      (Focus-IDS)
    • Re: "false positive" inanity
      ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
      (Focus-IDS)
    • Re: Secure Network Design (DMZ, LAN, etc)
      ... I'd like one outside the firewall and one ... I assumed I could make the first IDS ... should I have the IDS listening on the 192.168.1.0/24 network as well (web ... >Since the whole world will need access to your web servers, ...
      (Security-Basics)
    • Re: Need some information on HIDS!
      ... I have already invoked such a scenario in some of my previous IDS ... What I had in mind is something like encrypting the whole ... network traffic, to prevent sniffing from intruders (let's say wall-to-wall ... analysing and displaying logs. ...
      (Focus-IDS)