Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor |
|---|---|
| Date: | Sat, 15 Oct 2005 07:23:59 +1300 |
Tim Holman wrote:
2) Problems with false positives, as by using pattern matching signatures, there is always a chance that these patterns also appear in valid traffic
Huh?? "IDS have false positives and IPS don't"??? Yeah - right.
3) Management overheads. An IDS can only be a reasonably effective prevention method if there is someone on hand 24/7 to monitor logs and take immediate action on intrusions. Even then , the intrusion has got in, as admins very rarely use the active blocking features of an IDS (namely sending RST packets to kill connections, or modifying upstream ACLs), as these are too likely to have an effect on valid traffic
4) There is absolutely no protection for rate-based attacks (SYN, TCP, UDP floods)
Yup - IPS have paid more attention to that alright.
5) Without maintaining a L3/4 connection/state table, there is no way an IDS can be truly stateful. 100% statefulness means that everything from the initial SYN to the final RST/FIN packet of a connection is stored in a connection table. This requires the device to be INLINE, and operating at L3. This is the only way a protection device can provide effective defence against L3 attacks. An offline IDS cannot do this.
??? IDS cannot be stateful??? Sorry - they can.
I would recommend looking at IPS products instead, so something that you can postion inline and get immediate value from.
-- Cheers
Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
------------------------------------------------------------------------ Test Your IDS
| Previous by Date: | RE: IDS and Spywares, Omar A. Herrera |
|---|---|
| Next by Date: | Re: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor, Joel Esler |
| Previous by Thread: | Re: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor, Jason |
| Next by Thread: | Re: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor, Joel Esler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |