- Mythbuster busts his own tale
- 10 open source companies to watch
- Sony recalls 73,000 Vaio laptops
- Tool to evade China's Web censorship
- Chrome and Firefox and add-ons
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.
As I mentioned in a previous column, there’s a new set of draft documents from the Computer Security Resource Center of the U.S. National Institute of Standards and Technology (NIST).
SP 800-94, “Guide to Intrusion Detection and Prevention (IDP) Systems” is intended to assist organizations in understanding intrusion detection system (IDS) and intrusion prevention system (IPS) technologies and in designing, implementing, configuring, securing, monitoring, and maintaining intrusion detection and prevention (IDP) solutions.
It provides practical, real-world guidance for each of four classes of IDP products: network-based, wireless, network behavior anomaly detection software, and host-based. The publication also provides an overview of complementary technologies that can detect intrusions, such as security information and event management software.
It focuses on enterprise IDP solutions, but most of the information in the publication is also applicable to stand-alone and small-scale IDP deployments. The publication replaces NIST SP 800-31, Intrusion Detection Systems.
The document was written by Karen Kent and Peter Mell and has the following structure:
1. Introduction
2. Intrusion Detection and Prevention Principles
3. Overview of IDP Technologies
4. Network-Based IDP
5. Wireless IDP
6. Network Behavior Anomaly Detection Software
7. Host-Based IDP
8. Using and Integrating Multiple IDP Technologies
9. IDP Product Selection
Highlights of the recommendations (quoted from the Executive Summary) include:
* Organizations should ensure that all IDP components are secured appropriately.
* Organizations should consider using multiple types of IDP technologies to achieve more comprehensive and accurate detection
and prevention of malicious activity.
* Organizations planning to use multiple types of IDP technologies or multiple products of the same IDP technology type should
consider whether or not the IDPs should be integrated.
* Before evaluating IDP products, organizations should define the requirements that the products should meet.
* When evaluating IDP products, organizations should consider using a combination of several sources of data on the products’
characteristics and capabilities.
As usual, the document includes a glossary (Appendix A), a list of acronyms (Appendix B) and an extensive list of print and online resources pertaining to IDP systems and charts showing vendors of various types of products:
M. E. Kabay, PhD, CISSP-ISSMP is Program Director of the Master of Science in Information Assurance at Norwich
University.

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
The ROI and TCO Benefits of Data Deduplication for Data Protection in the EnterpriseThis paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...
Harnessing the power of communications to increase workplace performanceDue to the convergence of IT and telecommunications technologies, the business workplace has been...

We have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment