martin_roesch
VP and chief architect, Cisco's Security Business Group

Video: False Positives and False Negatives within IPS

Opinion
May 5, 20141 min

Chalk Talk discussion shows why they occur when detecting malicious threats

Intrusion Prevention Systems are designed to detect and block malicious traffic in a network or on an endpoint. The most critical function that these systems provide is the ability to make a judgment about the nature of a network flow, determining whether the traffic is legitimate or malicious.

The most common metric for evaluating the efficacy of an IPS/IDS is the detection rate. As one might guess, the detection rate is the number of intrusions detected by system divided by the total actual network intrusions, expressed as a percentage. Top intrusion prevention systems today can achieve detection rates of close to 100%.

Understanding the efficacy of these tools is critical when evaluating their business value and comparing one IPS solution with another. In this video, we define intrusion detection rate and explore where these systems fail, namely false positives and false negatives.

martin_roesch
VP and chief architect, Cisco's Security Business Group

Martin Roesch founded Sourcefire in 2001 where he was Chief Technology Officer (CTO) and a member of its Board of Directors. He is now vice president and chief architect for Cisco's Security Business Group. For more than a decade, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats, applying his knowledge of network security to network threat analytics and network forensics for numerous government and multinational customers. A respected authority on intrusion prevention and detection technology and forensics, he is the author and lead developer of the Snort Intrusion Prevention and Detection System (www.snort.org) that forms the foundation for the Sourcefire Next-Generation IPS. For more than a decade, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats, applying his knowledge of network security to network threat analytics and network forensics for numerous government and multinational customers. Roesch holds a B.S. in Electrical and Computer Engineering from Clarkson University.

More from this author