|
||||||||||||||||||||||||||
|
RESEARCH CENTERS
Applications
Careers Convergence Data Center LANs Net/Systems Mgmt. NOSes Outsourcing Routers/Switches Security Service Providers Small/Med. Storage WAN Services Web/e-commerce Wireless/Mobile SITE RESOURCES
Daily News
Newsletters This Week in NW Tests/Reviews Buyer's Guides Opinion Forums Special Issues How to/Primers Case Studies Network Life Encyclopedia IT Briefings TODAY'S NEWS
|
|
/ Three tips for reducing false alarms
If you decide to dive into intrusion-detection systems, these tips might help reduce your level of false positives and false alarms: 1. Map your network For example, if you have Apache Web servers, you should tell the IDS not to look for attacks that are based on Microsoft Internet Information Server vulnerabilities on those servers. If you've patched a server for Code Red, tell the IDS not to bother reporting Code Red attacks on that server. 2. Firewall your IDS Unfortunately, there's no point and nothing you can do with the information - you can spend all day complaining about port scans, and it won't do any good. The less traffic the IDS sees, the less it can complain about. 3. Use reporting tools - Joel Snyder Related LinksApply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.
|
||||||||||||||||||||||||