IDS mailing list archives
Re: IPS, alternative solutions
From: Mike Frantzen <frantzen () nfr com>
Date: Wed, 22 Sep 2004 12:22:01 -0400
The way I see it, an IPS can attempt to contain your infestation and help reduce your legal exposure from outbound attacks that would otherwise make it to your partners... This is a value I can quantify and the best use case I have seen for IPS. The problem I have with it is that a properly implemented firewall can most likely do the same and provide much better overall value.
One of the spots where an IPS beats a firewall hands down is on the interior of a large organization. I've seen too many large disfunctional companies that compartmentalize their departments by placing firewalls between each and every one. Marketing and sales can't access engineering project schedules and feature lists on the engineering web server. Engineering can't access the support database to look for common issues and trends. No one can access their department's machines from their laptop when in a conference room... etc etc We end up with an authoritarian system where the firewalls inhibit the communication inside the company. An IPS can maintain the security compartmentalization and containment without impeding the free flow of information between departments. I know I've bitched and moaned that some companies just don't talk between departments. And sometimes, they actually can't talk between departments. .mike frantzen@(nfr.com | cvs.openbsd.org | w4g.org) PGP: CC A4 E2 E8 0C F8 42 F0 BC 26 85 5B 6F 9E ED 28 -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
Current thread:
- Re: IPS, alternative solutions, (continued)
- Re: IPS, alternative solutions Scott Wimer (Sep 15)
- Re: IPS, alternative solutions Jason Haar (Sep 16)
- Re: IPS, alternative solutions Alex Butcher, ISC/ISYS (Sep 15)
- Re: IPS, alternative solutions Andy Cuff (Sep 16)
- Re: IPS, alternative solutions Johann_van_Duyn (Sep 15)
- RE: IPS, alternative solutions Palmer, Paul (ISSAtlanta) (Sep 17)
- Re: IPS, alternative solutions Jason (Sep 17)
- RE: IPS, alternative solutions Murtland, Jerry (Sep 17)
- RE: IPS, alternative solutions Cure, Samuel J (Sep 21)
- Re: IPS, alternative solutions Jason (Sep 22)
- Re: IPS, alternative solutions Mike Frantzen (Sep 22)
- Re: IPS, alternative solutions Devdas Bhagat (Sep 27)
- Re: IPS, alternative solutions Thomas Ptacek (Sep 29)
- Re: IPS, alternative solutions Kyle Maxwell (Sep 23)
- Message not available
- Re: IPS, alternative solutions Jason (Sep 26)
- Re: IPS, alternative solutions p z (Sep 27)
- Re: IPS, alternative solutions Jason (Sep 30)
- Re: IPS, alternative solutions Jason (Sep 22)
- RE: IPS, alternative solutions Stuart Staniford (Sep 29)