what do IDS analysts work on?

From: sponge (yosponge_at_yahoo.com)
Date: 10/27/03


Date: 26 Oct 2003 19:27:16 -0800

On Mon, 27 Oct 2003 01:17:13 GMT, Rowdy Yates
<rowdy.yates@no-spam-please.com> wrote:

>Hi ng. This may sound like a really dumbass question, so forgive the
>ignorance. I am new to this.
>
>
>I am reading Stephen Northcutt's book "Network Intrusion Detection" -
find
>the subject very interesting but am wondering. he talks about n-code
and
>creating signature filters e.t.c..
>
>are ids analysts/firewall expert's working mostly on unix os? or are
there
>ones that work on windows as well.
>
>ry,

My experience is that more is being done on Linux since you are
considering firewalls as well as IDS/IPS, but that is changing. The
trend in product for both is toward custom ASIC boxes for NIDS and
network firewalls; many PCs and other off-the-shelf hardware have some
serious limitations in high-saturation systems. However, there has
also been an increase in host-based IDS and IPS in the last year or
two for both Linux and especially Windows products.

If you're completely new to IDS, I suggest trying PC-based Snort. You
can have it in Linux or Windows flavors. It has some pretty severe
limitations -- which is why it's free versus upwards of a million
bucks for some IDS' -- but is good for learning or if you are on a
budget.

Sponge
Sponge's Secure Solutions
www.geocities.com/yosponge
My new email: yosponge2 att yahoo dott com



Relevant Pages

  • Re: thinking about trying out linux
    ... Linux by a long shot. ... I'm not sure what you are looking for here in limitations. ... games then you may want to setup a dual boot with windows so you ... As for windows doc files there are ...
    (alt.os.linux)
  • Re: How to install a font onto Windows Vista.
    ... am never too far from Linux :-). ... on windows although I am not sure if there are any dedicated windows users ... windows for its limitations I have found some gold amongst the dross: ... in Parallels Desktop -- strictly for that Space Cadet ...
    (news.software.readers)
  • Re: Firewall & IDS Questions
    ... Both are Linux based, and are free- SmothWall also produce a software ... > recommend running a serious firewall or IDS on a windows system. ... >> Which is and where could I download the best free firewall and IDS ...
    (comp.os.linux.security)
  • Re: IDS 11.5 licence question: virtual versus physical processors ?
    ... Maximum 2 CPU's and 4 Gb RAM ... IDS Workgroup Edition ... Unix, Linux and Windows only. ...
    (comp.databases.informix)
  • Re: Future of IT in Lebanon
    ... working knowledge of Indian programmers DNA, nor of their intuitive Java ... > So Longhorn is not an experiment and Linux is an experiment? ... another chapter in the Windows story, and the Microsoft marketing machine is ... > application opens, Check the about, it says Microsoft Visual Basic 6.3. ...
    (soc.culture.lebanon)