Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

RE: IPS comparison

Subject: RE: IPS comparison
Date: Tue, 6 Sep 2005 20:23:52 +0100 (BST)
Actually...  
It is either or when it comes to being in-line. Why
you ask? 1) Cost and 2) Infrastructure... both of
which I have to fight for. From a cost perspective...
I can deploy IDS without really purchasing anything
new... I recycle some hardware, put on Linux and throw
snort on it and I am good to go. IPS... I don't think
so.

Infrastructure wise... its a much easier sell to
deploy passive taps that just copy data than it is to
put an IPS inline which can possibly have a bad affect
on traffic.

I would prefer both... IDS inline with IPS to use as
validation of IPS blocking or to be able to more
adequately create IPS signatures (by taking packet
captures with ethereal or something).

-Hassan

--- Frank Knobbe <frank@knobbe.us> wrote:

 but I'll take IPS wherever I can
get it thank you. If one can't afford IPS... then
I
guess going the forensics only route is better
than
nothing. 

If you can't get apple you take an orange? Remember,
these are different
tools. You can very well have an IPS as a filter and
an IDS to verify
that the filter works. It's not an either-or
situation. Different tools
for a different job.


Cheers,
Frank


-- 
Ciscogate: Shame on Cisco. Double-Shame on ISS.



Send instant messages to your online friends http://uk.messenger.yahoo.com 

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>