IDS mailing list archives

Re: IDS testing methodologies


From: Mike Lyman <mlyman-security () comcast net>
Date: Fri, 02 Jan 2004 18:03:39 -0600

On Fri, 2004-01-02 at 08:52, Alvin Oga wrote:
in my book ... ( small world ) .. an IDS is not very useful, because, the
cracker is already in your network ... game over ...

Don't forget that once in, you still have to get him out. If the cracker
is in, the game has only just begun. If the guy has touched more than
one system, IDS can still play a major roll here, especially your home
grown IDS systems that are tailored to your environment. 

-- 
Mike Lyman <mlyman-security () comcast net>


---------------------------------------------------------------------------
---------------------------------------------------------------------------


Current thread: