Intrusion Detection Systems White Papers

Intrusion Detection Systems: Network IDS: To Tailor, or Not to Tailor

Overview Intrusion Detection Systems (IDS) identify attacks on a company’s resources. These IDS devices watch points in the company’s network infrastructure (network intrusion detection), or operate on a specific company asset (host based intrusion detection). These products detect attacks by comparing incoming activity to rule sets and patterns in search of hostile activity (signature based) or by comparing incoming activity against a known baseline in search of out-of-the- ordinary usage (anomaly based). Both signature and anomaly based intrusion detection are resource intensive. IDS resources include CPU, Network interface card (NIC), Memory (RAM), Storage (Hard Drive, SANS, etc), and, an overlooked end analyst. This user is often the most under-appreciated component of the IDS design as well as the most important. The analyst must find details and make correlations between multiple information sources.

Further White Paper Details
PublisherSANS Institute File FormatPDF, requires Acrobat Rdr 5
Date PublishedMarch 2002 Downloads8
FormatWhite Papers   
Topics
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: