[Agenda]
[Background]
[History]
[Classical]
[Modern]
[Purpose]
[IDS]
[Hardware]
[Software]
[Managment]
[Market]
[Policy]
[Qualities]
[Concl]
Network based intrusion detection
Intrusion detection doesn't succeed very much as a really useful & efficient tool at customer sites
IDS running on a host
The use of sniffers is made difficult by switched networks
Common case
IDS using branch circuits
Copy from one strand to another
Practical difficulties
Not yet common
IDS embedded in network devices
Use of sniffers possible in network devices
Example: Netflow switching with Cisco IOS, embedded NetRanger-light
Intrusion detection should become part of traffic screening in network devices
® ©
Hervé Schauer Consultants
1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 14 -