|
|||||||||||
|
Re: IDS is dead, etc
From: Bennett Todd <bet(at)rahul.net>
Date: Fri Aug 08 2003 - 13:15:47 EDT 2003-08-08T12:37:24 Scott Wimer:
No disagreement there. I don't presume software without error. I do maintain, however, that by combining tight configuration control with complete abstinance from known-bad software, you can raise the barrier sufficiently high that the attacks that succeed will be so wildly new and out of left field that your IDS would be no more help than your firewall. IDSes detect known problems; they're the "anti-virus scanners" of the network. Given such a setting, an IDS is still a great idea, as an educational tool, but it's not helping to tighten your protections, because it won't alarm on anything that succeeds. -Bennett
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT |
||||||||||
|
|||||||||||