Will Intrusion Detection Be Enough?

Posted by arlene

It would be wonderful if this could close by claiming victory in the war on intruders. You know by now that perfect security is impossible. You’ve had a chance to see how scanners, system-level tools, and network IDSs are able to catch some hacks but miss others. Your job is to know the types of […]

Which Product Has the Best Nose? continue…

Posted by arlene

RealSecure
ISS is already the market leader in scanning tools with SAFESuite. RealSecure is a widely used network IDS that complements ISS’s other offerings. Like NetRanger, RealSecure supports remote sensing stations, called engines, that report to a central console. Naturally, communication between engines and the console are cryptographically protected using a shared pass phrase. It shows […]

Which Product Has the Best Nose?

Posted by arlene

An Infoworld test reported in the May 4, 1998 issue rated products as follows:

IBM’s outsourced solution using NetRanger
ISS Real Secure
Network Flight Recorder (NFR)
Abirnet Session Wall

The study by the Infoworld team announced a suite of 16 well-known network attacks that they tried against the products. Only NFR caught all of the attacks. The team used the […]

Tracing the Path of Activity Can Be Difficult continue…

Posted by arlene

Still, this seems to be something that an IDS can track. As long as a path can be found from the source buffer to the final memory storage location written to the socket, the IDS will be able to detect that data has been compromised. Before you get another cup of coffee or tea, consider […]

Tracing the Path of Activity Can Be Difficult

Posted by arlene

An IDS traces the path of activity so that an operation can be traced back to a specific user. In other words, the IDS will look at more than one event to make a policy decision. This process is much different from an OS that relies on the credentials of the running process at the […]

Alexa CounterFeedBurner Counter