Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: RE: RE: IDS (was: FW appliance comparison)

RE: RE: IDS (was: FW appliance comparison)

From: Bill Royds <bill_at_royds.net>
Date: Wed, 1 Feb 2006 15:45:33 -0500

 The quote below is the heart of the problem. Most IT shops these days see the
word programming (or even scripting) and give you the sign of the cross.
Computer people don't know how to program these days and it is the kiss of death
for anything to say "just a little programming".

In some places, anyone who knows how to program is almost seen as a security
risk, almost a dreaded "hacker". That is why people ask for $80K SIM systems.
They want someone else to tell them how to pick out the important data out of
log files. A 20 line Perl program is much too complex.

-----Original Message-----
From: Marcus J. Ranum
Sent: Monday, January 30, 2006 7:22 PM
 <snip>

Seriously, though, 1 gig of compressed data per hour
means a bunch of different stuff; namely that you were
compressing it (which is fairly CPU and memory intensive)
on the fly -- so you could just as easily be doing something
else with it like running it through a stoplist or something
to prune out the stuff you know is garbage. Yes, that is
site-specific stuff and to do it right we're talking a little
bit of programming -- not rocket science type programming;
more like an awk script.

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Feb 02 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]