While Gartner is ready to write off IDS products as useless, we think they can play a meaningful role in larger networks when implemented and used correctly. IDS won’t help you recognize an attack, but when there has been a breach they can be real timesavers.
When last we discussed the relative worth of intrusion-detection systems on this page, we said we would reserve judgment pending our second review of the products.
At the time, Gartner was creating a flap by saying IDS systems are a waste of money because they flood users with false positives, a conclusion we had reached in our first test of IDS products in November 2002.
Now that we’ve published our second review of IDS products, we’re ready to weigh in on the debate about whether IDS systems are worthwhile: Yes, but . . . IDSs still generate too many false positives, and they are not for everyone.But if you know what you’re doing and have realistic expectations they add value.
On the false-positive front, Network World Test Alliance member Joel Snyder, a senior partner at Opus One in Tucson, Ariz., says the systems in this latest test generated gigabytes of alerts over the two-month test period. There were times when they were spitting out 100,000 alerts per day.
That said, the products did offer better tools to handle the flood. “With flexible grouping and display options, and automated upgrade and downgrade of alert information, we could make our way through the thousands of alerts we got each day,” Snyder says.
But he qualifies that as only a baby step forward. “They are better than they used to be, but only slightly. You can’t use IDS to alert you to when something bad is happening because you simply get too many alerts for that,” he says. “But IDS is good for forensics, finding the details when you know something bad has happened.”
For example, if you see a server disk has filled up with Metallica songs, you can use IDS to paw through the relative information to identify how the cretins reached the server and then go plug that rat hole, Snyder says.
But, he points out, you need employees devoted to security to get the most out of these systems, and you need detailed security policies and network knowledge for IDSs to make a difference. Said another way: These systems are for more-sophisticated shops.
So while Gartner is ready to write off IDS products as useless, we think they can play a meaningful role in larger networks when implemented and used correctly. IDS won’t help you recognize an attack, but when there has been a breach they can be real timesavers.




