Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

What if they are already in?

1 REPLY
New Member

Re: What if they are already in?

Glad to see you also had problems posting earlier.

If they are already in? I have deployed sensors throughout my internal network; it monitors the segments on which my unix servers, my intel servers sit. I monitor the perimeter, and I also monitor my perimeter with the corporate network.

I have other sensors on various parts of the network; we have customers that are categorized under various security levels and I configure the sensors appropriately.

I'm just guessing at your question, but I think you might be hinting at the host IDS solution; tripwires are fine but HIDS are an area that needs a whole heap of development; the best hids being those that simulate application stacks and can intercept attacks exactly as the targetted process would.

For example an Oracle HIDS that would interpret Oracle Attacks just like an Oracle server would.

and so forth....

ISS claims to be pursuing this with vim and vigor.

84
Views
0
Helpful
1
Replies