Educause Security Discussion mailing list archives

Re: IDP/IDS products


From: "Consolvo, Corbett D" <cc72 () TXSTATE EDU>
Date: Tue, 16 Sep 2008 16:39:46 -0500

Tipping Point, inline
We do use it as one way to shun hosts
Very few false positives, we create exceptions when appropriate
Tipping Point was in place before I got here
No known bad issues.
In general I am very pleased with Tipping Point although it took a little bit of time to get used to as I was 
originally a Snort user.

Thanks,
Corbett Consolvo
Texas State University

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Robert 
Riley
Sent: Tuesday, September 16, 2008 2:05 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] IDP/IDS products

We are seeking peer feedback on the use of Intrusion Detection/Prevention systems.

If your organization has deployed an enterprise IDP/IDS, are you:

1. Using the product inline or in bypass mode?
2. Are you using the product to shun hosts?
3. How are you managing false positives?
4. Which product do you use and what was your selection criteria?
5. Have you documented any known issues with the product?

Please feel free to contact me offlist if you prefer.

Thank you.
--
Robert Riley
Information Security Professional
University of Notre Dame

Current thread: