Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: IDS is dead, etc

From: Sam f. Stover <sstover(at)iwc.sytexinc.com>
Date: Fri Aug 08 2003 - 12:19:21 EDT


> A perfectly implemented firewall allows no protocols through for

Ok - I'll bite... Are you talking platonic perfect or worldly perfect?   If you mean platonic perfect, I'll agree, but given your statement below, I think you mean perfect w/ regard to a properly configured network i.e. possible in the "real" world.

How does this address 0-day attacks on services that weren't previously vulnerable? Granted a strings searching IDS might not help you there, but a true protocol based IDS like NFR might alert you to something that wasn't an issue before you implemented your "perfect" firewall.

I guess my real question is how to keep your firewall perfect? The instant you drop it in place, you'll have to stay ahead of every hacker out there to keep it perfect... An an IDS is a great tool to assist in that pursuit. Maybe I'm picking nits, but I've always thought of an IDS as a great passive device that will always be there to sniff your traffic in for when something new pops up...

> But given suitable systems configuration, it is possbile to have a

Also, isn't every IDS implementation an educational tool to some degree?

SfS



S.f.Stover
sstover@iwc.sytexinc.com

  • application/pgp-signature attachment: PGP.sig
Received on Mon Aug 11 10:37:00 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library