Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



IDS: Re: OSSIM as IDS

Re: OSSIM as IDS

From: dogten <dogten_at_d3fcon.org>
Date: Wed, 21 May 2008 16:49:44 -0500

Tremaine Lea wrote:
> Unfortunately, that's true of most IDS worth the name. Whether one is
> looking at Tipping Point, Sourcefire or another commercial offering,
> you're looking at a pretty good investment of time.
>
>
> ---
> Tremaine Lea
> Network Security Consultant
> Intrepid ACL
> "Paranoia for hire"
>
>
>
> On 21-May-08, at 10:21 AM, dkny_at_noah.com wrote:
>
>> Good, but a lot of work to get it in place.
>> David
>>
>> Quoting online_preeti_at_yahoo.com:
>>
>>> Dear All,
>>>
>>> Is that anyone has worked on OSSIM as an open source for intrusion
>>> detection?
>>>
>>> Regards
>>> Preeti
We had a bad experience with OSSIM on high load networks, too many bells
and whistles. EasyIDS seems to be a better fit for us and comes with
wizard based configuration for Barnyard integration.

-- 
-dogten http://blog.memoryoffset.com
"I have not failed. I've just found 10,000 ways that won't work." 
- Thomas Alva Edison (1847-1931)
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------
Received on May 22 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]