Firewall Wizards mailing list archives

Re: future of IDS


From: Vern Paxson <vern () ee lbl gov>
Date: Fri, 16 Oct 1998 10:18:53 PDT

With the likelihood that more and more hubs are going to
disappear and be replaced by switches, where does that leave the humble
IDS that can no longer see all the traffic it needs to, to do its job?

THe IDS folks have been aware of this pending problem for a while.
The basic approaches are (1) use an explicit tap on the switch, (2) build
the IDS into the switch (or get the switch to cooperate with the IDS),
(3) get the end hosts to chip in and function as IDS sensors.

                Vern



Current thread: