Re: Any IDS Recommendations?

From: Karl Levinson, mvp (levinson_k_at_despammed.com)
Date: 07/16/05

  • Next message: Miha Pihler [MVP]: "Re: Custom rights"
    Date: Sat, 16 Jul 2005 15:33:17 -0400
    
    

    "S. Pidgorny <MVP>" <slavickp@yahoo.com> wrote in message
    news:uaJrYUeiFHA.2904@tk2msftngp13.phx.gbl...

    > I see you have managed to convince the auditors that DMZ isn't the best
    > place to install the sensors because all traffic there is encrypted.
    However
    > I might suggest that this creates and excellent opportunity to come up
    with
    > tight IDS rule set: everything that is not on the list of (encrypted)
    > protocols is potential security breach. And seriously consider internal
    > network: first of all, NIDS will generate a lot of interesting
    information -
    > like curious grads that believe they're h@x0rz and stuff like that.
    Secndly,
    > the next IT security audit will require that anyway.

    Note that internal networks can be as challenging to monitor and give as
    many false alarms as putting sensors outside your firewall.

    And encrypted traffic does not necessarily have to be impossible to monitor.
    There are solutions that will let you unencrypt and monitor encrypted
    traffic, if you feel it is in your best interest to do so.


  • Next message: Miha Pihler [MVP]: "Re: Custom rights"

    Relevant Pages

    • Re: Any IDS Recommendations?
      ... > place to install the sensors because all traffic there is encrypted. ... > protocols is potential security breach. ... Note that internal networks can be as challenging to monitor and give as ... And encrypted traffic does not necessarily have to be impossible to monitor. ...
      (microsoft.public.security.virus)
    • Re: Any IDS Recommendations?
      ... > place to install the sensors because all traffic there is encrypted. ... > protocols is potential security breach. ... Note that internal networks can be as challenging to monitor and give as ... And encrypted traffic does not necessarily have to be impossible to monitor. ...
      (microsoft.public.security)
    • Re: query on multiple fields of same type?
      ... Each monitor has ports for sensors, ... The sensors can be level or velocity or h2s etc. ... I understand seperating each into a "velocityA" table is correct but then ... Then it's multiple conditions of 5+ sensor tables dates' ...
      (microsoft.public.access.queries)
    • Re: ASUS M2N-E mobo and openSUSE 10.2
      ... The only thing I miss is a possibility to monitor CPU-temperature. ... I can monitor CPU with the k8temp module. ... output from 'sensors' in a terminal under Ubuntu 7.04 64-bit gives: ... Adapter: PCI adapter ...
      (comp.os.linux.hardware)