When you buy a sports car, it's a no-brainer that you'll take it for a test drive to make sure you like the way it handles, the comfort level and its performance. And if you're like me, when purchasing a security . . . . When you buy a sports car, it's a no-brainer that you'll take it for a test drive to make sure you like the way it handles, the comfort level and its performance. And if you're like me, when purchasing a security product for your company, you show the same due diligence to make sure you're getting the performance you need. My company recently tested and acquired a network-based intrusion-detection system (IDS). Over the past few months, I've received many e-mails from readers asking me to explain the performance-testing methodology I used, so I've decided to share how I tested our network-based IDS. (A network-based IDS server watches traffic destined for all host systems on a subnet, while a host-based IDS typically runs on each host system to be protected.) Performance is only one possible criterion for choosing an IDS. Depending on the level of expertise of you and your staff and the amount of resources available, your requirements and testing criteria may be different from mine. You might focus on ease of use and strong reporting, ease of creating new attack signatures or price. The link for this article located at Computer World is no longer available. . Assess the efficacy of your cybersecurity solution by employing a structured approach to performance metrics for threat detection frameworks.. Intrusion Detection, Performance Evaluation, Security Testing, Network Security. . Anthony Pell
The National Infrastructure Protection Center (NIPC) is releasing this notice to provide system administrators developing information about a potential new network security vulnerability. The NIPC is still reviewing this information both for accuracy and to determine the level of threat. Further . . . . The National Infrastructure Protection Center (NIPC) is releasing this notice to provide system administrators developing information about a potential new network security vulnerability. The NIPC is still reviewing this information both for accuracy and to determine the level of threat. Further information will be provided, as it becomes available. This assessment only applies to those networks that use an Intrusion Detection System (IDS). As always, users are advised to keep their software current by checking their vendors' websites frequently for new updates, and to check for alerts put out by NIPC, CERT/CC, and other cognizant organizations. Initial reports indicate that a software package has been identified which, if used maliciously, may disable a victim's computer or network's IDS by flooding it with Internet traffic emanating from several random Internet Protocol (IP) addresses simultaneously. The attack attempts to flood a targeted network or computer with too many "false positives" for IDSs to handle, thereby potentially causing the IDS to become inoperative. Once this is accomplished, a hacker might try to take advantage of the failed IDS to locate and exploit an unrelated vulnerability on the victim's system, perhaps with the goal of seeking root access. The link for this article located at NIPC is no longer available. . The APTC notifies system operators regarding a possible IPS vulnerability due to harmful applications and advises caution.. Intrusion Detection System, NIPC Alerts, Network Flooding, Security Threat, Network Security. . Anthony Pell
This article focuses on several host-based intrusion detection systems that are available on Linux. In particular, I will cover some of the basics of installing setting up these packages, how they are useful, and in what circumstances they can be . . .. This article focuses on several host-based intrusion detection systems that are available on Linux. In particular, I will cover some of the basics of installing setting up these packages, how they are useful, and in what circumstances they can be used. This article assumes a basic knowledge of systems security. In particular, I will assume that the most basic security measures have already been taken to secure a host against intrusion from the internet. The link for this article located at SecurityFocus --Â Â is no longer available. . Explore host-centered breach detection schemes tailored for Linux platforms, including guidance on setup and insights on how they bolster security.. Host-Based Intrusion Detection,Linux Security Tools,Cyber Defense,Intrusion Detection Systems. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.