Intrusion Detection Systems mailing list archives
RE: BlackICE IDS
From: broyds () home com (Bill Royds)
Date: Mon, 6 Dec 1999 21:09:49 -0500
I have been investigating commercial IDS systems for several months. More and more I have come to the
conclusion that you have to
create a network design that will allow IDS's to work well before installing the software.
Forcing the IDS to listen on the main backbone with a huge amount of mainly legitimate traffic puts a lot of
strain on the system
without necessarily increasing its accuracy. Putting it most closely to the assets one wants to protect and designing
the network to
force traffic past the IDS before communicating with the asset will be much more productive.
It is a little like the design of physical security systems and alarms. You do have a lock and guard on the
front door (firewall).
You don't put the motion detector in the main lobby next to the door but nearest to the Rembrandt in the boardroom.
When I studied graph theory in University, one of the most important concepts/theorems was based on the min
cut-max flow principal.
One needs to involve network IDS at exactly those points in a network where the minimum bandwidth meets the maximum
flow of packets
that one is interested in. By analysing cut points of your network and redesigning it to have choke points, one can get
a much
better bang for your buck of intrusion detection.
-----Original Message-----
From: owner-ids () uow edu au [mailto:owner-ids () uow edu au]On Behalf Of
pingman
Sent: Monday, December 06, 1999 11:27
To: Greg Shipley; Robert Graham; Marcus J. Ranum
Cc: John S Flowers; ids () uow edu au
Subject: Re: IDS: BlackICE IDS
mjr and folks
i am in the midst of getting a multisegment ids system, and have read
through this thread.
as a customer, i must say i am confuse on which one to settle with now.
is it that all ids ain't ready at present.
i know it is all up to one's individual decision. nevertheless, any comments
from the experts?
cheers
al
Current thread:
- RE: Network Utilization discussion..., (continued)
- RE: Network Utilization discussion... Ryan M. Ferris (Dec 06)
- Re: RE: Network Utilization discussion... Misha (Dec 06)
- IDS Dafunquia, Facundo (Dec 07)
- Re: IDS Trevor Schroeder (Dec 07)
- Re: RE: Network Utilization discussion... Ron Gula (Dec 07)
- RE: Network Utilization discussion... Ryan M. Ferris (Dec 06)
- Half-Assed Review site Troy Billington (Dec 28)
- Half-Assed Review site Troy Billington (Dec 28)
- Re: BlackICE IDS Marcus J. Ranum (Dec 05)
- Re: BlackICE IDS -reply mht () clark net (Dec 06)
- Re: BlackICE IDS pingman (Dec 06)
- RE: BlackICE IDS Bill Royds (Dec 06)
- Sharing Information [Was: BlackICE IDS] John S Flowers (Dec 06)
- new subscriber... Bernard Clairmont (Dec 07)
- Re: Sharing Information [Was: BlackICE IDS] Ron Gula (Dec 07)
- ISS RealSecure upgrade problem Xiong Shao Jun (Dec 07)
- Re: ISS RealSecure upgrade problem Jackie Chan (Dec 08)
- RE: new subscriber Jeff Oliver (Dec 08)
