Re: Intrusion Detection

From: HSKarim (HSKarimat_private)
Date: Tue Apr 14 1998 - 20:49:21 PDT

  • Next message: Bennett Todd: "Security Policy (was Re: how to do intrusion detection right)"

    In a message dated 98-04-14 23:22:32 EDT, you write:
    
    << You may find some interesting things. But again you are
    << correct that this may take to much time for most people, thats why large
    << companies (should) have a full time security staff.
    The draw back from bein on the full-time security staff from a large company
    is that you never have time to "break out the network sniffer and take a look
    _for_your_self_ whats going on". Back in the good ole' SysAdmin days security
    was fun cause you actually had time to learn. Its the "follow up" that
    mentioned that takes up all of the time.
    
    <hmmm-deepthoughts>
     A packaged IDS would save me the time of having to write it myself. Plus
    management would agree "... because the vendor said so."
    </hmmm-deepthoughts>
    
    >> > mjr.
    >> > --
    >> > Marcus J. Ranum, CEO, Network Flight Recorder, Inc.
    >> > work - http://www.nfr.net
    >> > home - http://www.clark.net/pub/mjr
    >> > 
     
    >> Aleph One / aleph1at_private
    >> http://underground.org/
    >> KeyID 1024/948FD6B5 
    >> Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01  >>
    
    -- Hassan
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 12:54:35 PDT