Re: IDS Implementation

From: hans m41 (mayer41_at_m05.yer.at)
Date: 10/08/05

  • Next message: gaur_ms_at_yahoo.co.in: "Re: SSH through Firewall"
    Date: Sat, 8 Oct 2005 09:49:27 +0000 (UTC)
    
    

    In article <1128708076.627808.94530@z14g2000cwz.googlegroups.com>,
     <rneshko@idmr.com> wrote:
    >I have been asked by my company to research different IDS solutions,

    i have experience since years with iss from realsecure
    imho it's not manageable - the resource for manageing is to high
    iss is more an ids than an ips.
    i also played around with snort. snort gives more flexibility
    at writing own rules, but is less manageable than iss.
    there are a lot of false positives.
    it tooks serveral weeks to reduce the amount of events
    to a reasonable number of entries. and i have only 12 c-classes
    of ip-addresses.

    i have also heard from mcafee's ips, but never worked with it.
    mcafee has it's own hardware box and can communicate with checkpoint.
    as i heard mcafee's ips should be fine and adminstrative costs
    sould be small. but somebody else could give his experience
    with mcafee. my next try would be mcafee.

    my experience, all ids/ips are still at the beginning, even if
    they are several years old.

    best regards
    hans

    -


  • Next message: gaur_ms_at_yahoo.co.in: "Re: SSH through Firewall"

    Relevant Pages

    • RE: Which is the most widely deployed commercial IPS
      ... For network-based IPS I saw a report a while back that said McAfee had ... the biggest marketshare with ISS a close second and Cisco third. ... Which is the most widely deployed commercial IPS ...
      (Focus-IDS)
    • Re: Proventia G400
      ... We are currently evaluating IPS vendors in order to ... ISS Proventia was one of the first to ... Security Centre. ...
      (Focus-IDS)
    • Re: Proventia G400
      ... I also did some extensive evaluation of various IPS sometimes ago.I ... of Proventia, but later I found most of them are mud slinging type ... so you would need a separate DDOS device (ISS ...
      (Focus-IDS)
    • Re: How to choose an IDS/FW MSS provider
      ... in the IPS space. ... The central PC based CPU appract of Netscreen IDP, Checkpoint & ISS ...
      (Focus-IDS)
    • RE: GB IDS solutions
      ... We considered ISS but had heard their product ... Does anyone know of GB network IDS solutions other than ISS? ... I will be needing GB capable sensors but believe there must be another way ...
      (Focus-IDS)