|
|
Subject:
On the need of having intrusion detection system( firewall already install) ?
Category: Computers > Security Asked by: aloy-ga List Price: $4.00 |
Posted:
05 May 2002 10:39 PDT
Expires: 13 May 2002 20:35 PDT Question ID: 13221 |
I wish to install an intrusion detection system to enhance the companys network security. However the manager has said that the company already has a firewall and doesnt see why she should authorise the purchase of an intrusion detection system as well. Wish to find out: 1)what an intrusion detection system can do and why it is necessary to have one as well as a firewall. The manager has good knowledge of IT, but knows little about network security issues. |
|
There is no answer at this time. |
The following answer was rejected by the asker (they reposted the question). | |
Subject:
Re: On the need of having intrusion detection system( firewall already install) ?
Answered By: answerguru-ga on 05 May 2002 11:33 PDT |
Hi there! Our search returned the following results: This site is a thorough definition of what exactly an IDT is, what is does, and how it is different from a firewall: &quot;Though they both relate to network security, an IDS differs from a firewall in that a firewall looks out for intrusions in order to stop them from happening. The firewall limits the access between networks in order to prevent intrusion and does not signal an attack from inside the network. An IDS evaluates a suspected intrusion once it has taken place and signals an alarm. An IDS also watches for attacks that originate from within a system.&quot; <a href="<a href="http://www.webopedia.com/TERM/I/intrusion_detection_system.html">http://www.webopedia.com/TERM/I/intrusion_detection_system.html</a>"><a href="http://www.webopedia.com/TERM/I/intrusion_detection_system.html">http://www.webopedia.com/TERM/I/intrusion_detection_system.html</a></a> Feel free to post a clarification if there is something you don't understand :) Hope this helps! answerguru | |
| |
|
Reason this answer was rejected by
aloy-ga:
The answer given was too brief and did not really answer my question... |
The following answer was rejected by the asker (they received a refund for the question). | |
Subject:
Re: On the need of having intrusion detection system( firewall already install) ?
Answered By: tripitaka-ga on 12 May 2002 13:11 PDT |
Hello, I can appreciate that you need to justify the requirement for an IDS to your manager. You could try explaining that a firewall and an IDS do very different things, and both are essential as parts of a comprehensive security setup. A firewall,as you know, blocks certain traffic depending on type, source etc. They are good, but not perfect, at preventing comprimises of your security. Assuming that someone will find a hole in a misconfigured firewall, or use a different attack vector such as email trojans, social engineering (actually walking up to the machine and comprimising the console) or any of a number of techniques, it is important to be able to detect when a successful attack has taken place so that you can limit the damage. This is where the IDS comes in. A good IDS, such as tripwire (<a href="<a href="http://www.tripwire.com">http://www.tripwire.com</a>"><a href="http://www.tripwire.com">http://www.tripwire.com</a></a> - it's free!) will monitor various system files and processes, watching for typical changes an attacker may make. For instance, an attacker may modify or replace programs which will allow them to pass undetected, or gain further control. A tripwire will notice any such action and notify the administrator, namely you. IDS systems can monitor servers, switches, routers and other systems, all of which are vital to your security. Always remember that a firewall, no matter how well put together, can never be perfect, and indeed only protects you from attacks originating from networks on the other side of it. Always assume that you will get cracked, and look to an IDS to tell you exactly what happened. Then, you can make damage assessments, and more importantly trace the intruder's footsteps to make sure such an attack cannot succeed again. There are some good articles at <a href="<a href="http://www.cert.org">http://www.cert.org</a>"><a href="http://www.cert.org">http://www.cert.org</a></a>, such as <a href="<a href="http://www.cert.org/homeusers/intruder_in_computer.html">http://www.cert.org/homeusers/intruder_in_computer.html</a>"><a href="http://www.cert.org/homeusers/intruder_in_computer.html">http://www.cert.org/homeusers/intruder_in_computer.html</a></a> which looks at basic system security with IDS, and a far more comprehensive look at the subject here: <a href="<a href="http://www.cert.org/tech_tips/intruder_detection_checklist.html">http://www.cert.org/tech_tips/intruder_detection_checklist.html</a>"><a href="http://www.cert.org/tech_tips/intruder_detection_checklist.html">http://www.cert.org/tech_tips/intruder_detection_checklist.html</a></a> Hope this helps, good luck. tripitaka |
Reason this answer was rejected by
aloy-ga:
The answers given are again too brief |
|
Subject:
Re: On the need of having intrusion detection system( firewall already install) ?
From: interceptor-ga on 05 May 2002 12:04 PDT |
Hello aloy-ga, You can help both yourself and your manager with this document that is found at the Internet Security Systems Website at (http://documents.iss.net/literature/mss/Managed_Intrusion_Protection.pdf) This document states everything that you are looking for, has recommendations for such products, and also has block diagrams that help graphically explain the process. I hope that this additional information helps you in what you need to do! Thanks for using Google Answers and have a great day! No Google search terms were used in this comment. This website is one of the companies that our company (the company I work for and not Google) does business with. Regards, Interceptor-ga |
Subject:
Re: On the need of having intrusion detection system( firewall already install)
From: yaron-ga on 07 May 2002 10:52 PDT |
An IDS is like a network antivirus. If it has a current signature file it can tell you if you are under attack. Take for example the recent Code Red NIMDA trojans. Assuming you have an internal IIS server which is behind a firewall (within your DMZ most likely), you should allow access to it. An IDS will be able to tell you if you are under a Code Red attack. If your budget is tight and you are fluent with Unix (Linux/FreeBSD/Solaris), I suggest that you will check out snort (http://www.snort.org). You can take an old PC running Linux and snort which will give you a feeling of IDS without investing anything but your time. |
If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you. |
Search Google Answers for |
Google Home - Answers FAQ - Terms of Service - Privacy Policy |