Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




focus-ids logo IDS mailing list archives

Re: IDS testing methodologies
From: Mike Lyman <mlyman-security () comcast net>
Date: Fri, 02 Jan 2004 18:03:39 -0600

On Fri, 2004-01-02 at 08:52, Alvin Oga wrote:
in my book ... ( small world ) .. an IDS is not very useful, because, the
cracker is already in your network ... game over ...

Don't forget that once in, you still have to get him out. If the cracker
is in, the game has only just begun. If the guy has touched more than
one system, IDS can still play a major roll here, especially your home
grown IDS systems that are tailored to your environment. 

-- 
Mike Lyman <mlyman-security () comcast net>


---------------------------------------------------------------------------
---------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]