Firewall Wizards mailing list archives

Re: future of IDS


From: "Joseph S. D. Yao" <jsdy () cospo osis gov>
Date: Fri, 16 Oct 1998 16:00:15 -0400 (EDT)

Now, after all this preamble, I do actually have a question for the great
minds to ponder. With the likelihood that more and more hubs are going to
disappear and be replaced by switches, where does that leave the humble
IDS that can no longer see all the traffic it needs to, to do its job?

Some switches claim to have a "monitor" port for just this purpose.
But if two segments are communicating with two other segments flat out
at a significant portion of 100 Mb, how are you going to capture all
that?

You may need to have a monitor on each segment, and [depending on the
spare bandwidth on your primary network] perhaps a separate back-end
network over which the IDS systems will communicate.

Progress is not necessarily inexpensive.  ;-/

--
Joe Yao                         jsdy () cospo osis gov - Joseph S. D. Yao
COSPO/OSIS Computer Support                                     EMT-A/B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.



Current thread: