Educause Security Discussion mailing list archives

Re: Intrusion Detection Recommendations


From: Jason Richardson <A00JER2 () WPO CSO NIU EDU>
Date: Tue, 9 Aug 2005 11:47:33 -0500

We're using Snort with a BASE front-end (set up similar to what you are
doing with span port) and a Lancope Stealthwatch Anomaly Detection
appliance.  The Lancope device has worked out pretty well for us, but I
wish that they would write in some signature based detection.  The also
sell a console that aggregates Lancope sensor data as well as Snort
data.  intend to eval the console in September.  I can recommend this
company because of the superior tech support that we have received from
them - really top notch so far.

Another company to look at (that I'm surprised not to have heard anyone
mention yet) is Tipping Point.  If I had it to do over again I probably
would have looked at the Tipping Point appliances very hard because they
do the signature and anomaly based detection all in one place.

---
Jason Richardson
Manager, IT Security and Client Development
Enterprise Systems Support
Northern Illinois University

Current thread: