Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: IDS is dead, etc

From: Bennett Todd <bet(at)rahul.net>
Date: Fri Aug 08 2003 - 11:13:27 EDT

2003-08-07T16:49:10 Barry Fitzgerald:
> Oh yes, and someone (perhaps tongue-in-cheek) mentioned that a > properly configured firewall removes the need for an NIDS.

Perhaps you're referring to my comment:

	2003-08-06T14:57:53 Bennett Todd:

> 2003-08-06T07:39:28 Paul Schmehl:

> I have to chime in and say that I couldn't possibly disagree more.

Understandable. I really shouldn't have included that remark; or else I should have expanded on it. I didn't say "properly configured firewall", I said "really perfectly implemented firewall", and I meant something different by that, although I neglected to explain.

A perfectly implemented firewall allows no protocols through for which there are vulnerable implementations inside. That means it's impossible to implement a perfect firewall if you're going to allow Windows users to have internet access. You can come moderately close, with a hideous amount of work, but you'll still be very exposed, and an IDS will be critical reinforcement of your flawed security.

But given suitable systems configuration, it is possbile to have a perfect firewall, and if you do then an IDS is just an educational tool, and would probably be most useful in concert with a honeypot.

Do you need help?X

-Bennett

  • application/pgp-signature attachment: stored
Received on Fri Aug 8 12:04:47 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library