Home > Ask the Security Experts > Questions & Answers > Identifying the best IDS for a company's needs
Ask The Security Expert: Questions & Answers
EMAIL THIS

Identifying the best IDS for a company's needs

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 April 2002
I want to deploy an intrusion-detection system for my company. Which is the best available and most economical? Also, can you tell me which one will best suit my company's needs if we are using a terminal server on our end of the Internet?


>
EXPERT RESPONSE

Intrusion-detection systems are the focus of a lot of time and attention these days. Many companies are deploying them without regard to which IDS best meets their needs. Your question shows that you don't want to just fill in a check box saying that you have IDS but instead want to deploy the right solution. First off, IDS come in two general flavors -- host based and network based. I'll address your question on the network-based IDS product side, since it gets so much attention these days.

Unfortunately, the quick answer to your question is, "It depends." You see, different IDS products meet different needs. If you are on a limited budget but want a good amount of technical flexibility and the means to define your own attack signatures, go for the open source Snort tool (www.snort.org). If you like Snort, but want more support or are restricted from buying an open source tool (as some companies sadly are), you should check out the commercialized Snort offerings of Source Fire (www.sourcefire.com).

If you are looking for a good product that offers excellent detection capabilities and technical depth, you should check out the Enterasys Dragon (http://www.enterasys.com/ids/). Another worthy product is the Network Flight Recorder (www.nfr.com). Finally, if you are looking for a very shrink-wrapped tool, look into the ISS RealSecure product.

My bottom-line recommendation is that you spend some time piloting IDS using the freeware Snort tool in your environment. As you get used to network-based IDS using this free tool, you'll better understand your particular requirements and can spend the dollars on a commercial solution (or stay with the free Snort). That way, you learn for less and can make an educated decision on your product needs.


For more information on this topic, visit these other SearchSecurity.com resources:
Online Event Transcript: Intrusion detection with Ed Yakabovicz
Best Web Links: Intrusion detection
Featured Topic: Intrusion-detection systems


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts