Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

IDS criticisms kindle debate

Intrusion detection is more trouble than it's worth, Gartner says
 

Sign up to receive Security Resource Alerts

June 23, 2003 (Computerworld) -- A Gartner Inc. report that called intrusion-detection systems a failed technology that isn't cost-effective evoked fervent reactions last week from users, vendors and analysts on both sides of the argument.

Some concurred with Gartner's position, saying IDSs are difficult to manage and generate far more data than is useful.


"I couldn't agree more," said Eric Beasley, network administrator at Baker Hill Corp., an application service provider in Carmel, Ind., that replaced its IDS with a Web application firewall. "IDS did little to increase our overall security," he said. "All I got was information overload."


Others said that despite the problems, it's premature to completely write off IDS technology.


"I think that broadly describing IDS as a market failure because of product shortcomings is a bit alarmist," said Eric Goldreich, manager of technology at Latham & Watkins LLP, a law firm with 1,500 attorneys in Los Angeles. "The existing solutions are not perfect, but they are much better than nothing at all."


An IDS typically operates behind a firewall looking for patterns or signals in network traffic that might indicate malicious activity. Over the past two years, the sensor-based technology has been gaining increasing attention from users who see it as an added layer of protection against attacks that breach other defenses, such as firewalls and antivirus software.


However, several problems with IDSs make the technology more trouble than it's worth, said Richard Stiennon, a Gartner analyst and author of the IDS report.


The biggest is the fact that the systems impose a heavy management burden on companies by requiring full-time monitoring, Stiennon said. The tendency of such systems to generate a very large number of false alarms also adds to this burden, he said. The technology's inability to monitor traffic at transmission rates greater than 600Mbit/sec. can also be a problem, especially with widely deployed high-speed internal networks, according to Stamford, Conn.-based Gartner.


Because of these issues, IDSs will become obsolete by 2005, Stiennon predicted. Instead of spending on technologies that detect intrusions, companies would be more prudent to invest in technologies that are designed to prevent intrusions from occurring in the first place, such as "deep-packet-inspection" firewalls, he added.


"I don't know about obsolete, but IDS is not all the rage it was two to three years ago, that's for sure," said Michael Engle, vice president of information security at Lehman Brothers Holdings Inc.


When New York-based Lehman Brothers installed an IDS about three years ago, the system generated more than 600 alerts daily, he said. Since then, the firm has invested in an event-correlation technology for analyzing IDS data and distilling it into a more manageable volume, Engle said.


"I think it takes an inordinate amount of time to get meaningful IDS data from those systems, hence our investment in event-correlation software," he said.


Continued...
1 | 2 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
IDS criticisms kindle debate
"Need help sorting through the hype of cloud computing? Here's some IDC research on the benefits, barriers -- and what..." Read more...
Read more Security posts or See all Blogs
Update: AMD spins off manufacturing to cut costs, raise funds
IBM launches Bluehouse, a Facebook for business
iPhone grabs top smart phone spot
More top stories...
Microsoft's (un)secret weapon for winning the BI battle
Microsoft scales out SQL Server 2008, wants to 'democratize BI'
Oracle tries to step up on high-end databases
Too much junk food, too little exercise and a 24/7 tether to technology? Your body ain't happy, friend. Let us count the pains.
Instruments on the surface of Mars have detected falling snow that is likely evaporating before it reaches the planet.
One positive development stemming from the collapse of Wall Street may be a boost in interest in computer science and IT careers among students who were previously interested in financial services jobs.
Getting new software installed on Linux doesn't have to be hard, but it can differ depending on what you're installing.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
The Enterprise Search Zone
Software as a Service Zone

Ads by TechWords

See your link here
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Intercept Spam & Viruses
Download this whitepaper to learn how to outsmart spam & viruses, compliments of MessageLabs.
(Source: MessageLabs) Register for a complimentary 30 day trial of MessageLabs' new managed Anti-virus and Anti-spam security solutions. MessageLabs guarantees complete protection against all known and unknown email threats. By providing 24 hour support, your business can increase productivity and decrease risk.Register now for a complimentary trial and receive a free datasheet.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
The Guide to Troubleshooting Application Problems
Putting the Right Model in Place to Better Balance IT Supply and Business Demand
Six Project Metrics Every CIO Should Know for Application Delivery Success
View more whitepapers