IDS mailing list archives
Re: IDS vs. IPS deployment feedback
From: Stefano Zanero <zanero () elet polimi it>
Date: Thu, 23 Mar 2006 21:47:20 +0100
Andrew Plato wrote:
IPS is far from immature. The first in-line IPS was BlackICE Guard. I installed one of the first in late 1999.
The first IDS paper dates in the 80s. Still, I would not say IDS, or IPS, are a mature technology. It's not a point of being old - it's a point of being EFFECTIVE.
A well tuned IPS can be pretty lean on false positives.
Standard considerations apply, as for IDS
a few POSSIBLE disruptions due to false positives, or getting hacked and 0wn3d and losing your business.
You are implying that the likelyhood of the IPS stopping a nasty attack are way above the likelyhood of false positives. This is exactly what you're trying to prove ;)
Firewalls are not IPSs.
I see less and less difference among the two.
IDS may not be dead, but its value is diminishing.
IPS is just the reactive sort of IDS, so the debate on IDS vs. IPS is not very interesting...
Moreover, the value of an IDS diminishes even more if you lack in-house analytical capabilities.
If you don't have those capabilities, how are you going to setup an IPS, exactly ?
These are, of course, my opinions. And naturally, I have a vested interest in people buying more IPSs - because I sell them.
I don't :) Stefano ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Current thread:
- IDS vs. IPS deployment feedback watsont (Mar 20)
- Re: IDS vs. IPS deployment feedback Jean-Philippe Luiggi (Mar 23)
- <Possible follow-ups>
- RE: IDS vs. IPS deployment feedback Carey, Steve T GARRISON (Mar 21)
- Re: IDS vs. IPS deployment feedback nightelfhunter (Mar 21)
- RE: IDS vs. IPS deployment feedback Andrew Plato (Mar 23)
- Re: IDS vs. IPS deployment feedback Stefano Zanero (Mar 27)
- RE: IDS vs. IPS deployment feedback Cojocea, Mike (IST) (Mar 27)
- Re: RE: IDS vs. IPS deployment feedback xris375 (Mar 27)
- RE: RE: IDS vs. IPS deployment feedback Andrew Plato (Mar 28)
- Re: RE: IDS vs. IPS deployment feedback Devdas Bhagat (Mar 29)
- Re: RE: IDS vs. IPS deployment feedback Jean-Philippe Luiggi (Mar 31)
- Re: RE: IDS vs. IPS deployment feedback Devdas Bhagat (Mar 29)
- Re: RE: RE: IDS vs. IPS deployment feedback xris375 (Mar 30)
- Re: RE: RE: IDS vs. IPS deployment feedback Sanjay Rawat (Mar 31)
- Re: Re: RE: RE: IDS vs. IPS deployment feedback trashcanmn (Mar 31)
- RE: RE: IDS vs. IPS deployment feedback Andrew Plato (Mar 31)