IDS mailing list archives

RE: HIPS Comparative ?


From: "Marc Maiffret" <mmaiffret () eeye com>
Date: Tue, 4 Dec 2007 15:06:07 -0800

A more HIPS specific review that is very recent:
http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci1
280028,00.html

-Marc

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Stefano Zanero
Sent: Saturday, December 01, 2007 5:06 AM
To: Focus-Ids Mailing List
Subject: Re: HIPS Comparative ?

Albert R. Campa wrote:
SC mag did a product test on various HIPS agents. Also see if you can
get your hands on some Gartner documentation.
http://www.scmagazineus.com/Anti-malware-management-2007/GroupTest/31/

Am I the only one that finds the equation HIPS = anti-malware a bit
biased ?

Anti-malware is just a fraction of what an HIPS should do, and it's the
part which is similar to what antiviruses already do. In fact, many of
those products have little difference from your common antivirus suite.

An HID/PS on the other hand should be broader, encompassing also
detection of attack activities that have nothing to do with malware
being deployed in a drive-by fashion.

Stefano


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to
http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw 
to learn more.
------------------------------------------------------------------------



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------


Current thread: