Firewall Wizards mailing list archives

Re: Intrusion Detection Systems, Best of breed?


From: "Talisker" <talisker () networkintrusion co uk>
Date: Sat, 22 Dec 2001 18:08:27 -0000

Rob
As no one else has answered (on list) may I give my point of view.  I have
no intention of mentioning specific products but would like to suggest that
you look at what you need from an IDS, dividing your requirements into
mandatory and desirable, then see which products best meet your needs.
narrow the field down to around 3 and evaluate them over some time.

Network IDS are still quite immature and vary considerably, also market
share (IMHO) doesn't always mean it is a good IDS.

Things to look for are
How you intend to manage your solution, training, console requirement for
forensic collection ease of use etc
Resources you have available to run it, manpower, training etc
Compatibility with your network (most important).
The ability of the IDS, which would hopefully extend beyond pure signatures
into protocol awareness and statefullness.
Cost
A few of us threw a list together at Sans last year
http://www.networkintrusion.co.uk/bof_toby.htm

good luck in your quest, IDS are extremely valuable assets but need plenty
of tender loving care and careful selection

take care
-andy
http://www.networkintrusion.co.uk
----- Original Message -----
From: "ROB SLAUGHTER" <rslaughter () cpsts com>
To: <firewall-wizards () nfr com>
Sent: Thursday, December 13, 2001 8:05 PM
Subject: [fw-wiz] Intrusion Detection Systems, Best of breed?


I was checking in to Best of Breed intrusion detection products and was
wondering if anyone had suggestions on which manufacturers truly have a
"Best of Breed" product.  If you know of any that you feel strong about
(possitive) could you please supply me with a few links?  Thanks,

Rob Slaughter
Sales Account Manager
CPS Technology Solutions
10205 51st Avenue North
Plymouth, MN  55442
Phone:  763-278-9620  or  877-348-0916
Fax:  763-553-9058
rslaughter () cpsts com


_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://list.nfr.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://list.nfr.com/mailman/listinfo/firewall-wizards


Current thread: