IDS mailing list archives
Re: Current IDS problems
From: Terry Vernon <tvernon24 () comcast net>
Date: Sat, 22 Oct 2005 04:12:30 -0500
False positives is one, the algorythms used to scan traffic is another, un-flexibility is another big one.
Most of these problems are easily solved except for when you make a commercial product you have to "dumb it down" so the end users can handle it. I'm designing an IPS for a large customer whom we all know and you would figure these people should know it all. I have to put miles of if statements in the code with accompanying error messages to describe why you cant do this or that. When we can open up the throttle and not worry about the end user we can have some awesome stuff on the market. Take "vi" the text editor for example. To a newb it's terrible but to someone who's used to it it's a necessity. Most of the truly useful features in these products wind up on the cutting room floor because the decision makers don't want to do it for money or time constraints. To tell you the truth your better stuff is coming from smaller companies and not symantec, cisco, etc... Anyone who begs to differ works for one of the said companies. The executives keep tight leashes on the development departments.
Terry Vernon CTO/Senior Developer Sprite Technologies crazy frog crazy frog wrote:
false positives.allthough we need to fine tune it to reduce this stuff. On 10/19/05, zero <zeroboy () arrakis es> wrote:Hi all, I would like to know what are the problems people working with IDS sees in them. I mean, what are the things you hate about IDS, think simply you feel are plain wrong or that they should be another way to it. Al comments are greatly appreciated :) Thxs in advance. ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. -------------------------------------------------------------------------- ting ding ting ding ting ding ting ding ting ding ding i m crazy frog :) ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly?Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.------------------------------------------------------------------------
------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly?Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------
Current thread:
- Current IDS problems zero (Oct 18)
- Re: Current IDS problems Mark Ryan del Moral Talabis (Oct 19)
- Re: Current IDS problems crazy frog crazy frog (Oct 21)
- Re: Current IDS problems Dhruv Soi (Oct 24)
- Re: Current IDS problems Terry Vernon (Oct 24)
- Re: Current IDS problems Nakul Aggarwal (Oct 26)
- RE: Current IDS problems Vipul Kumra (Oct 27)
- <Possible follow-ups>
- Re: Current IDS problems barcajax (Oct 19)
- RE: Current IDS problems Thompson, Jimi (Oct 26)