Re: Writing a paper on Network and Host based IDS

From: Gonzalo A. Cisternas M. (gonlo@hotmail.com)
Date: 03/27/03


From: "Gonzalo A. Cisternas M." <gonlo@hotmail.com>
Date: Thu, 27 Mar 2003 14:21:45 -0400

Inf you wish we can sit in a Sunday and review some implementations. I've
work with the CA IDS and an old one from NAI (Cybercop). But these are
pretty old, and now you can know more information about the current "state
of the art".

Gonlo

"Tim A." <tman@**NOSPAM**usa.com> escribió en el mensaje
news:Kk4ga.51$qi7.2855@eagle.america.net...
> Hello all,
>
> I am writing a paper on Intrusion Detection Systems and would like some
> advice/opinions/feedback.
>
> In my paper I will discuss two popular Host Based IDS and two popular
> Network Based IDS and compare their efficiency. It will highlight the
> positives and negatives to using both systems on the same network.
>
> If anyone would like to steer me in the right direction as I am just
> learning about IDS that would be greatly appreciated.
>
> Thanks,
> Tim
>
>



Relevant Pages

  • Re: Writing a paper on Network and Host based IDS
    ... > I am writing a paper on Intrusion Detection Systems and would like some ... > In my paper I will discuss two popular Host Based IDS and two popular ... > Network Based IDS and compare their efficiency. ... > positives and negatives to using both systems on the same network. ...
    (alt.computer.security)
  • Re: IDS and NMS
    ... Start by designing and installing a network. ... Next, a more detailed view of the network is required, so a NMS is ... the network administrator wants to see what ... This is where integrating the IDS console into the NMS makes sense. ...
    (Focus-IDS)
  • Re: "false positive" inanity
    ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
    (Focus-IDS)
  • Re: Secure Network Design (DMZ, LAN, etc)
    ... I'd like one outside the firewall and one ... I assumed I could make the first IDS ... should I have the IDS listening on the 192.168.1.0/24 network as well (web ... >Since the whole world will need access to your web servers, ...
    (Security-Basics)
  • Re: Need some information on HIDS!
    ... I have already invoked such a scenario in some of my previous IDS ... What I had in mind is something like encrypting the whole ... network traffic, to prevent sniffing from intruders (let's say wall-to-wall ... analysing and displaying logs. ...
    (Focus-IDS)