Intrusion Detection Systems Can Work--With Effort
In other words, your IDS is merely one tool among many for securing your network. Layering multiple security measures together is part of the well-balanced "defense in depth" strategy recommended by many security pros. Allen suggests that IT executives consider adding the following components to their security strategy: network-based intrusion detection sensors, host-based intrusion detection, a central reporting and monitoring console for IDS alerts and other network messages, firewalls, log file analysis and strong user authentication.
The key is making sure that you have adequate processes in place to manage the data generated by your IDS and to respond accordingly. "The IDS is only as good as the people watching the IDS," says Foundstone’s McClure. "If you’re not going to monitor it, you might as well buy a $50,000 doorstop." Rasmussen recommends that any IDS implementation should include clear processes for responding to alarms, policies governing network maintenance issues (such as IDS signature updates and operating system patches) and continued education of your network security staff.
Rasmussen also recommends starting small, with one or two IDS sensors at critical points on your network. That will make your IDS deployment small enough to be manageable, and give your network engineers time to learn the system and to tune it without getting swamped by thousands of alarms.
For his part, Williamson chose to test Arkansas State’s IDS in midspring, when network traffic was low, giving his engineers several months to get settled before activity picked up again when classes began in the fall. And he’s already starting to think of other uses for the IDS. They can adjust it to look for almost any type of network abuse, such as prohibited file-trading software. "If you wanted to, you could shut almost anything down," says Williamson. Not that he’s taking such a draconian approach to network management?but the IDS is a powerful lens with which to keep an eye on network problems, and that is clearly a reassuring thought.
$firstKeyword



