|
|||||||||||
|
Re: IDS is dead, etc
From: Scott Wimer <scottw(at)cylant.com>
Date: Fri Aug 08 2003 - 13:24:46 EDT Bennett, I think we are on the same page as to the utility of IDS systems. Where we differ is in our estimation of the level of vulnerability of software that is "known" to be good and secure. Over the course of the summer I've been given more insight into the gray and black hat world. The number of systems that are backdoored -- today, and the number of non-public vulnerabilities and exploits is slightly disturbing. I really like your description of NIDS as AV scanners for the network. That's classic. Although, some will argue that the more behavioral oriented NIDS have moved past that point. *shrug* A good NIDS is an invaluable tool for network managers. But, a NIDS is not the security "solution" that they are marketed as.
Regards,
Bennett Todd wrote:
>>The assumption that human beings can design, write, and install >>software without error is WRONG. > > > No disagreement there. I don't presume software without error. -- Scott M. Wimer, CTO Cylant www.cylant.com 121 Sweet Ave. v. (208) 883-4892 Suite 123 c. (208) 301-0370 Moscow, ID 83843 There is no Security without Control. --------------------------------------------------------------------------- Captus Networks - Integrated Intrusion Prevention and Traffic Shaping - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans - Automatically Control P2P, IM and Spam Traffic - Ensure Reliable Performance of Mission Critical Applications Precisely Define and Implement Network Security and Performance Policies **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo Visit us at: http://www.captusnetworks.com/ads/31.htm ---------------------------------------------------------------------------Received on Mon Aug 11 10:45:37 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT |
||||||||||
|
|||||||||||