IDS mailing list archives

RE: IDS Opinions


From: "NTL World - Chris Standard" <chris.standard () ntlworld com>
Date: Thu, 17 Jun 2004 22:02:17 +0100

I would choose an IDS that can at least detect simple backdoors such as BO2k
on well known ports as a starting point.

Test some of the solutions out there, there results can be interesting....

-----Original Message-----
From: Steve Massa [mailto:smassa () adelphia net] 
Sent: 02 June 2004 2:21 AM
To: 'Danislav Kostov'; focus-ids () securityfocus com
Subject: RE: IDS Opinions

I would not exclude Demarc from your short list. www.demarc.com provides
robust detection techniques in either hardware or software applicance
forms.  If you are familiar with snort (or nessus) this tool will go a
long way for your organization.
Cheers,
SPM

-----Original Message-----
From: Danislav Kostov [mailto:d.kostov () is-bg net] 
Sent: Tuesday, June 01, 2004 4:43 AM
To: focus-ids () securityfocus com
Subject: RE: IDS Opinions


Hi to all of you!
I've tried CA-IDS: http://www.ca.com/
Very nice tool with a lot of gadgets BUT:
Still expensive for some companies (license based on the connections),
Needs a lot of power (CPU+RAM) to take advantage of all the functions...
I recommend you to download the trial and test it yourself... and PLS,
share your opinion after that.

Best Regards,
Danislav Kostov

-----Original Message-----
From: Tarek Amr Abdullah [mailto:tabdullah () salec com eg] 
Sent: Sunday, May 30, 2004 10:39 AM
To: focus-ids () securityfocus com
Subject: RE: IDS Opinions

Crayola,

I recommend either ISS Proventia or Juniper NetScreen IDP. As I am not
with deploying IDSs unless they are high quality and reliable. Otherwise
if you choosed "Sourcefire's, Dragon (Enterasys), and Symantec's
manhunt." For financial reasons. Then I think you may deploy Snort
instead as it is open source, and also sourcefire is built upon snort. 

Best Regards,
Tarek Amr Abdallah

-----Original Message-----
From: crayola () optonline net [mailto:crayola () optonline net] 
Sent: Friday, May 28, 2004 10:23 PM
To: focus-ids () securityfocus com
Subject: IDS Opinions

Folks, 

I am currently in the middle of an RFP process to buy a new Network ids 
system for my company. I have narrowed it down to 

Sourcefire's, Dragon (Enterasys), and Symantec's manhunt. 

I would love to hear your opinions about these products if you use or 
have used them. Anything you can share would be great. I am really
looking 
for some nonsales type opinions about how they work in the real world. 

Thanks, 
Mike


------------------------------------------------------------------------
---

------------------------------------------------------------------------
---


------------------------------------------------------------------------
---

------------------------------------------------------------------------
---



------------------------------------------------------------------------
---

------------------------------------------------------------------------
---


---------------------------------------------------------------------------

---------------------------------------------------------------------------




---------------------------------------------------------------------------

---------------------------------------------------------------------------


Current thread: