Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Security
F E A T U R E  
Dragon Claws its Way to the Top

  August 20, 2001
  By Greg Shipley and Patrick Mueller

The Future of IDS

Lately there's a lot of buzz about pushing gigabit speeds and integrating IDSes (intrusion-detection systems) with custom hardware, but we believe that two of the most important issues have yet to be addressed in a mature manner: data aggregation and correlation, and event management.

As organizations begin to realize the importance of monitoring logs and performing queries on historical data, products that can tie firewall data, IDS data and system logs together will become more valuable. An IDS that picks up an attacker knocking on one firewall is one thing. That same attacker knocking on 20 firewalls around the world is quite another. As IDSes continue to mature, they should be able to use their distributed nature to craft more intelligent alerts and help classify attacks accordingly.

Another feature that is lacking in today's IDSes is the ability to manage events. For example, in our testing we used a simple forum package called phpnuke to keep communication paths open between us and DePaul's network admin team. Modern IDSes aren't designed to tie into operations-centric systems, so security staffers are left to play the cut-and-paste game. Eventually, IDSes will have to go the route that networking devices have gone: interoperability with larger frameworks. We hope the day will come when you can snap in a HIDS agent from one vendor and a NIDS sensor from another vendor and plug them both into a framework manager from a third vendor. For now, however, we're stuck doing much of the management ourselves.


   Page: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | Next Page

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers