[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Network Partitioning &
Intrusion Detection Systems
(1/2)
IP filtering is
proactive
security, Intrusion Detection is
responsive
security
Several Intrusion Detection Methods
Network-based IDS
Host-based IDS
Application-based IDS
Host-based & Application-based IDS
As difficult to deploy as proactive host-based security
Network-based IDS
Useful for application layer signatures detection
Going from host into network devices
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 30 -