Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: IPS, alternative solutions |
|---|---|
| Date: | Sun, 26 Sep 2004 06:04:36 +0530 |
On 22/09/04 12:22 -0400, Mike Frantzen wrote:
The way I see it, an IPS can attempt to contain your infestation and help reduce your legal exposure from outbound attacks that would otherwise make it to your partners... This is a value I can quantify and the best use case I have seen for IPS. The problem I have with it is that a properly implemented firewall can most likely do the same and provide much better overall value.One of the spots where an IPS beats a firewall hands down is on the interior of a large organization. I've seen too many large disfunctional companies that compartmentalize their departments by placing firewalls between each and every one. Marketing and sales can't
Which is broken behaviour in the name of security. People who need access to certain data for normal work related purposes must be given such access. Those who don't need access should not be given such access. I believe that this type of issue is largely caused by people equating firewalls with simple packet filters.
access engineering project schedules and feature lists on the engineering web server. Engineering can't access the support database to look for common issues and trends. No one can access their department's machines from their laptop when in a conference room... etc etc
Actually, that is broken firewall design and/or implementation. If the requirements of the various customers are not met, then the firewall is just an impediment to work, or it lets too much traffic through. In such cases, the company should be using proxies with proper authentication and logging to regulate traffic flow (IMHO firewalls should be a combination of packet filters and proxies anyway).
We end up with an authoritarian system where the firewalls inhibit the communication inside the company. An IPS can maintain the security compartmentalization and containment without impeding the free flow of information between departments.
No. an IPS is just an attempt at a proxy looking for bad things. In my book, this is equivalent to filtering untrusted user input for bad stuff instead of limiting it to known good stuff and removing the rest. This should not be acceptable behaviour for security enforcement management and/or personnel. Devdas Bhagat -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: free hIDS, or system assessment tools, Ty Bodell |
|---|---|
| Next by Date: | Re: free hIDS, or system assessment tools, Ben Nelson |
| Previous by Thread: | Re: IPS, alternative solutions, Mike Frantzen |
| Next by Thread: | Re: IPS, alternative solutions, Thomas Ptacek |
| Indexes: | [Date] [Thread] [Top] [All Lists] |