|
Source: Search Security Channel - Posted by Bill Keys
|
Once alert generation (intrusion detection) mode is enabled, the matter becomes complicated. Snort is no longer rendering or logging -- it has become a Traffic Intelligence System (TIS), as described in the last Snort Report. A TIS is valuable if it's trusted. Trust comes from being able to understand how a tool came to a certain conclusion. For example, if Snort reports seeing Attack X, you want to know how Snort made that judgment.
This article brings up some good points about intrusion detection. What do you feel is the state of intrusion detection software like Snort? Are they effective enough to implement on your network?
Read this full article at Search Security Channel
Powered by AkoComment! |