Skip Links

Evaluating the IDS options

By Deborah Radcliff, Network World
November 08, 2004 12:10 AM ET
  • Print

IDS and IPS monitoring technologies come in many flavors: anomaly detection, heuristics, traffic pattern analysis, application analysis, payload analysis, passive vs. active listening, and so forth. How is a buyer to choose?

Paul Proctor, vice president of the security and risk strategies practice at Meta Group, recommends weeding through the options by asking four key questions:

* What source of data you want to look at (network traffic, system logs, application logs, etc.)? This determines the type of monitoring that works in your environment.

•  What's the architecture of what you're trying to protect (distributed or centralized)? This determines whether you'll want agents or passive listening devices for network discovery. It also determines if you want in-line our out-of-line devices.

•  What's the mechanism to determine the intrusion? Is it anomaly-based or signature-based?

•  Your timeline. Do you want to detect before or use it for forensics after?

Back to review: "The evolution of IDS"

Read more about security in Network World's Security section.

  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Videos

rssRss Feed