|
|||||||||||
|
Re: Need recommendations about IDS Systems
From: Talisker <offthecuff(at)lineone.net>
Date: Wed Jan 29 2003 - 14:04:15 EST Hi Jenn You mention having an IDS on your DMZ and perimeter, it may be worth having one on the inside also depending on your budget and network topology.
As to selection, take your time and evaluate the contenders fully before you
make a final decision. Most of them have some really good features and
failings. It would take a far better man than I to suggest a particular IDS
that would suit your network based on what you have said. Snort is
mentioned and it is a phenomenal beastie but no IDS is really free, they
take a great deal of TLC in the form of tuning and management. I built my
website when I was in exactly the same boat as you, it started as just a
list of every IDS available, I then reduced the list to around 4 that suited
my network, then tested them extensively. They do vary greatly, but it's
great fun playing with them and understanding what you want from an IDS. My
pet hate at the moment is how they report events and whether there is
sufficient information for an analyst to understand what they are dealing
with.
BlackIce Guard (ISS)
Hope this helps
Taliskers Network Security Tools
I have been looking at a couple IDS systems and reading reviews. My head =
hurts :) Any recommendations ? I want something to sit inside my =
network, in the DMZ and outside. I want it to also email me and send =
information to my syslog server. OS doesn't matter. I can do nt or =
linux.
Thank you
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:39 EDT |
||||||||||
|
|||||||||||