ccrowell
03-24-2004, 07:00 PM
Looking for recommendations on intrusion detection software. I'm an administrator at an auto dealership and we have a lot if information ro protect. I've heard good things about Snort (doesn't hurt that it's free, either), but I have some concerns about ease of installing and using. Does anyone have any recommendations and a relatively inexpensive IDS that is somewhat easy to operate?
Greenstead
03-25-2004, 01:55 PM
Well, I'm not a network manager, but I would think twice about bothering with IDS unless there is some reason you have to believe you might be targetted by expert hackers e.g. if you were a bank, or goverment dept. There are not many 'serious' hackers and an auto parts database is probably not very interesting for them. But its up to you.
Many IDS generate so much data you cannot cope with it and it is generally legitimate traffic though unrecognisable at first. Try monitoring a simple home network - I use NAT routers, SPI firewall and firewalls on each PC - still I see traffic I cannot explain. I dread the idea of monitoring a company network.
More important I would say is to harden your edge connections, routers, firewalls, AV, critical updates, and strong authentication and control of user accounts and passwords. Most network damge is done by disgruntled employees. Real hacking by outsiders is rare unless you leave the doors open with a website, or wireless network.
Recommendation:
None