Skip Links

Network World

  • Social Web 
  • Email 
  • Close

NIST guide to IDP systems

NIST's 'Guide to Intrusion Detection and Prevention (IDP) Systems'
Security Strategies Alert By M. E. Kabay , Network World , 09/14/2006
Sign up for this newsletter now!

Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.

As I mentioned in a previous column, there’s a new set of draft documents from the Computer Security Resource Center of the U.S. National Institute of Standards and Technology (NIST).

SP 800-94, “Guide to Intrusion Detection and Prevention (IDP) Systems” is intended to assist organizations in understanding intrusion detection system (IDS) and intrusion prevention system (IPS) technologies and in designing, implementing, configuring, securing, monitoring, and maintaining intrusion detection and prevention (IDP) solutions.

It provides practical, real-world guidance for each of four classes of IDP products: network-based, wireless, network behavior anomaly detection software, and host-based. The publication also provides an overview of complementary technologies that can detect intrusions, such as security information and event management software.

It focuses on enterprise IDP solutions, but most of the information in the publication is also applicable to stand-alone and small-scale IDP deployments. The publication replaces NIST SP 800-31, Intrusion Detection Systems.

The document was written by Karen Kent and Peter Mell and has the following structure:

1. Introduction
2. Intrusion Detection and Prevention Principles
3. Overview of IDP Technologies
4. Network-Based IDP
5. Wireless IDP
6. Network Behavior Anomaly Detection Software
7. Host-Based IDP
8. Using and Integrating Multiple IDP Technologies
9. IDP Product Selection

Highlights of the recommendations (quoted from the Executive Summary) include:

* Organizations should ensure that all IDP components are secured appropriately.
* Organizations should consider using multiple types of IDP technologies to achieve more comprehensive and accurate detection and prevention of malicious activity.
* Organizations planning to use multiple types of IDP technologies or multiple products of the same IDP technology type should consider whether or not the IDPs should be integrated.
* Before evaluating IDP products, organizations should define the requirements that the products should meet.
* When evaluating IDP products, organizations should consider using a combination of several sources of data on the products’ characteristics and capabilities.

As usual, the document includes a glossary (Appendix A), a list of acronyms (Appendix B) and an extensive list of print and online resources pertaining to IDP systems and charts showing vendors of various types of products:

M. E. Kabay, PhD, CISSP-ISSMP is Program Director of the Master of Science in Information Assurance at Norwich
University.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.