RE: Recommending an IDS system

From: Josh Mills (JMills_at_cnbwaco.com)
Date: 03/03/04

  • Next message: Gulsher Bajwa: "Attack Trees"
    Date: Wed, 3 Mar 2004 08:48:04 -0600
    To: "AJ Butcher, Information Systems and Computing" <Alex.Butcher@bristol.ac.uk>, "Reza Kordi" <rk@4unet.net>, "Andy Cuff" <lists@securitywizardry.com>, "security-basics" <security-basics@securityfocus.com>
    
    

    We were on a netranger box and it was definetly solaris but when we switched the sales rep said it was now running on redhat. I will double check later today and see what it is actually running.

    -----Original Message-----
    From: AJ Butcher, Information Systems and Computing
    [mailto:Alex.Butcher@bristol.ac.uk]
    Sent: Wednesday, March 03, 2004 7:00 AM
    To: Josh Mills; Reza Kordi; Andy Cuff; security-basics
    Subject: RE: Recommending an IDS system

    --On 01 March 2004 17:18 -0600 Josh Mills <JMills@cnbwaco.com> wrote:

    > I have implemented a new cisco ids solution and i am very pleased with
    > it! the signatures are highly tunable for a commercial package and it
    > seems to be pretty stable. the sensor itself runs on redhat so maybe it
    > isnt that much different than snort.

    Is this Cisco's Secure IDS appliance? The last time I looked at them (Aug
    2002) they were running on top of Solaris x86 on Dell Poweredge hardware.
    The NIDS itself couldn't be more different from Snort; back then, it didn't
    give any information to allow the analyst to decide whether an attack was
    successful or not... :(

    I don't see any mention of a switch to RH for CSIDS on Cisco's website, so
    I'm a little confused...

    Best Regards,
    Alex.

    -- 
    Alex Butcher: Security & Integrity, Personal Computer Systems Group
    Information Systems and Computing             GPG Key ID: F9B27DC9
    GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9
    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
    any course! All of our class sizes are guaranteed to be 10 students or less 
    to facilitate one-on-one interaction with one of our expert instructors. 
    Attend a course taught by an expert instructor with years of in-the-field 
    pen testing experience in our state of the art hacking lab. Master the skills 
    of an Ethical Hacker to better assess the security of your organization. 
    Visit us at: 
    http://www.securityfocus.com/sponsor/InfoSecInstitute_security-basics_040303
    ----------------------------------------------------------------------------
    

  • Next message: Gulsher Bajwa: "Attack Trees"

    Relevant Pages

    • Re: [SLE] RE: Ticket [20040519430002952] e100 module parameters
      ... >>I switched to SuSE from RedHat quite a few years ago due to buggy ... don't just buy it, find a few problems, and switch to another distro! ... I remember when I was on RedHat - when they made major changes (which to their ...
      (SuSE)
    • Lockup and now screwy keyboard
      ... I have an system with an older Redhat 7.2 inhouse system. ... The mcahine booted back up fine and no errors were detected any of the log files. ... I switched to other machines on this switch and the keyboard dose fine. ...
      (RedHat)
    • Printing in ES 2.1
      ... We are migrating a server from HPUX 11 to Redhat 2.1 ES. ... options to the printer using the -o switch. ... how to get these options working or a version of CUPS that functions ...
      (RedHat)
    • Re: Help! : Linux Networking Guide
      ... Hub: Sends all data to every machine connected to it and then the machine ... Switch: Intelligently "switches" the data to the right port at the box, ... If you take a very easy-to-use graphical distro such as Redhat, ... to install the following things with it: ...
      (comp.os.linux.networking)
    • Re: Anyone planning to use Fedora in production?
      ... I used and loved redhat for years. ... Now I will switch to Debian or Gentoo. ...
      (RedHat)