Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



IDS: Re: Announcement: Alert Verification for Snort

Re: Announcement: Alert Verification for Snort

From: Michael Sierchio <kudzu_at_tenebras.com>
Date: Thu, 23 Oct 2003 19:28:43 -0700

Martin Roesch wrote:

> Yes. Separating the wheat from the chaff is becoming increasingly
> important in IDS as we all know, I'll be interested to see how the
> different techniques and approaches people are using to address this
> problem actually work in production.

Judgement and discrimination require human intervention. When I
hear those who say things akin to "intrusion detection doesn't
work," I think of the story of the guy who returned a violin
to the music store with the complaint, "this violin doesn't
play Mozart."

I like your term "nontextual" -- and the implication that
there's no substitute for an assessment of the assets we are
placing at risk, what their vulnerabilities are, what the
(known) threats are, etc. Managers want "plug and play"
because they have so little respect for our profession ;-)

---------------------------------------------------------------------------
Network with over 10,000 of the brightest minds in information security
at the largest, most highly-anticipated industry event of the year.
Don't miss RSA Conference 2004! Choose from over 200 class sessions and
see demos from more than 250 industry vendors. If your job touches
security, you need to be here. Learn more or register at
http://www.securityfocus.com/sponsor/RSA_focus-ids_031023
and use priority code SF4.
---------------------------------------------------------------------------
Received on Oct 24 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos