IDS mailing list archives

RE: Definition of Zero Day Protection


From: "Carey, Steve T GARRISON" <steven-carey () us army mil>
Date: Mon, 9 Aug 2004 12:07:50 -0500

My own personal opinion, based on 7 years of experience in intrusion detection, is that it is a marketing ploy.  Only 
way to ensure Zero Day Protection is to use a 'suite' of IDS tools and have an analyst looking at those logs 24/7 to 
find the Zero Day Exploit.  

Vendors can state they prevent Zero Day Exploits but to do that you can also stop legitimate traffic.  Maybe sometime 
in the future that can happen, but not today.

Steve Carey

-----Original Message-----
From: Teicher, Mark (Mark) [mailto:teicher () avaya com]
Sent: Sunday, August 08, 2004 8:48 PM
To: focus-ids () securityfocus com
Cc: Seanor, Joseph (Joe)
Subject: Definition of Zero Day Protection


What is Zero Day Protection, I think I understand the definition of Zero
Day Exploits.  But what is Zero Day Protection?  Another marketing blurb
or it can vendors actually offer zero day protection?   

Thank you for clarifying my confusion

/m

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE
IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE
IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------


Current thread: