IDS mailing list archives
Re: Target based IDS review and discussion in Information Security
From: Ron Gula <rgula () tenablesecurity com>
Date: Tue, 13 Jan 2004 21:34:04 -0500
I really like Cisco's approach of being able to react to an attack and gain info about a target system. I do think that such a reaction needs to be tempered so that it does not become a DOS. I also would not want to be the security guy asking IT for network privileges on their boxes so my Console could log into their boxes after a suspected attack has occurred. Having said that, we have a similar feature on our roadmap for the Lightning Console. Overall though, there are many advantages to being passive, active or maybe reactive and not one solution fits them all. We're trying to be flexible with the Lightning Console by letting people choose how much of any of those types of vuln detection they really want. Ron Gula, CTO Tenable Network Security --------------------------------------------------------------------------- ---------------------------------------------------------------------------
Current thread:
- Target based IDS review and discussion in Information Security Joel Snyder (Jan 08)
- Re: Target based IDS review and discussion in Information Security Martin Roesch (Jan 09)
- Re: Target based IDS review and discussion in Information Security Joel Snyder (Jan 09)
- Re: Target based IDS review and discussion in Information Security Jeff Nathan (Jan 12)
- RE: Target based IDS review and discussion in Information Security Craig H. Rowland (Jan 12)
- Re: Target based IDS review and discussion in Information Security Martin Roesch (Jan 13)
- RE: Target based IDS review and discussion in Information Security Craig H. Rowland (Jan 13)
- Re: Target based IDS review and discussion in Information Security Ron Gula (Jan 13)
- Re: Target based IDS review and discussion in Information Security Joel Snyder (Jan 09)
- Re: Target based IDS review and discussion in Information Security Andy Cuff [Talisker] (Jan 12)
- Re: Target based IDS review and discussion in Information Security Martin Roesch (Jan 12)
- Re: Target based IDS review and discussion in Information Security Martin Roesch (Jan 09)
- <Possible follow-ups>
- Re: Target based IDS review and discussion in Information Security Richard Bejtlich (Jan 13)
- RE: Target based IDS review and discussion in Information Security Teicher, Mark (Mark) (Jan 13)
