[Agenda] [Examples] [Network Partitioning] [Concepts] [Policy] [Process] [Organization] [HW-SW] [Cases studies] [Conclusion] [Resources]
[first slide] Network Partitioning & Intrusion Detection Systems (1/2) [previous slide] [next slide]

* IP filtering is proactive security, Intrusion Detection is responsive security

* Several Intrusion Detection Methods
o Network-based IDS
o Host-based IDS
o Application-based IDS

* Host-based & Application-based IDS IDS comparaison
o As difficult to deploy as proactive host-based security

* Network-based IDS
o Useful for application layer signatures detection
o Going from host into network devices


*********************************************************************
HSC ® © Hervé Schauer Consultants December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 30 -