About IDS tools

From: Renee Teunissen (thuis) (renee@home.wittenburg10c.nl)
Date: 07/31/01

Message-ID: <007f01c119fd$1b9d04a0$5908a8c0@ratnoot>
From: "Renee Teunissen (thuis)" <renee@home.wittenburg10c.nl>
To: <SECURITY-BASICS@securityfocus.com>
Subject: About IDS tools
Date: Tue, 31 Jul 2001 22:12:20 +0200


Currently I am investigating a propper way to implent an IDS in large
corporate network on about 20 locations with one central server location.

We have two different issues / projects.

1: to provide a service to detect internal intrusion attempts (to detect
"inside" hacks and network resource misuse). We have a lot of internal LANs
(eg, production, development, testing, etc) and wish to monitor the traffic
between those networks.
2: to provide a service to detect external intrusion attempts, packets that
go by a firewall, etc, etc. made by people using the extra-nets of
intra-nets (Cablemodem / DSL connected home workers, etc)

Are there reports of such implementations and what kind of products can
handle switched networks with 50K+ PC's and 3K+ servers/unixboxes across a
large corporate WAN. And are there know implemantation strategies? Please
give me your thoughts about this..


