Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




focus-ids logo IDS mailing list archives

RE: Question on resources needed to manage IDSes
From: "Morse, Greg" <gmorse () trigeo com>
Date: Wed, 3 Dec 2003 12:57:23 -0800

I am a vendor with a SEM solution and therefore bias, but I believe if you
automate the process  you don't need to add additional staff to manage and
respond to the alerts, IDS or otherwise. 

SEM is like having Data from Star Trek programmed with all the info from your
best person.  Then he reads every event record in every log across your
system, not just the IDS, processes it in real time, compares it to your
policies and if you have an active response set, it will immediately take
that active response to stop the attack.  Then write the normalized info to
the database for forensic analysis.

Just don't want you to think you have to keep building each car by hand when
there is an automated assembly line available.


Greg Morse
Director of Business Development
Eastern Region
TriGeo Network Security, Inc.
Office:  1-866-664-9292  ext. 124
gmorse () trigeo com
www.trigeo.com
_________________________________

For Contego product information and white papers go to: 
www.trigeo.com/publications.shtml
_________________________________


---------------------------------------------------------------------------
---------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]