IDS mailing list archives

Re: Changes in IDS Companies?


From: Eye Dius <nthlayer () yahoo com>
Date: 17 Oct 2002 07:26:25 -0000

In-Reply-To: <003101c27594$5de8e970$01000001 () SecurityConscious com>

- snip -

IDS vendors have not
been able to get false alarm/postive rates down to a level where
organizations would trust an IDS alert to enforce network policy.  

Nothing I've seen or read from these new vendors gives me any reason to
believe they have cured the cancer of IDS - false alarms/positives.

What are some of the big reasons for false positives? What is preventing 
new or existing vendors from fixing this problem?


Current thread: