PDA

View Full Version : Need advice on network and host based IDS


ggratto
February 28th, 2003, 03:55 PM
Need advice on network and host based IDS solutions.
Have you used one?
Pros and cons?

LowWaterMark
February 28th, 2003, 07:15 PM
At work, my company made an investment in RealSecure from ISS (http://www.iss.net/products_services/enterprise_protection/). We tried two different pieces, the network based sensors and the server based ones. We had a lot of difficulty getting much out of the network sensors given the complexity of our networks (a large number of switched vlans) and ultimately decided the best way was to put the IDS on every server. (The idea being an attack had to have a target... Monitoring every target gives you a greater chance of catching the intrusion, versus trying to monitor the network wire directly.)

You didn't say whether you were talking about a home or an enterprise solution, so, I figured I'd give you information from a large scale business network perspective, as it's more interesting than installing an IDS on a small home setup.

ggratto
March 4th, 2003, 10:45 AM
I am looking for a enterprise solution
Currently looking at

Cisco
Dragon
SHS
symantec

Thanks for the info.