Home > Security Channel FAQs > Snort > Snort FAQ for Resellers > What is Snort? > Why is the Snort IDS still alive and thriving?
FAQs: Snort:
EMAIL THIS
 START   SNORT FAQ FOR RESELLERS   MORE INFORMATION ON SNORT   
Snort FAQ for Resellers


What is Snort?
<< PREVIOUS | NEXT >>: Is Snort right for the IDS needs of all clients?

Why is the Snort IDS still alive and thriving?

14 Jan 2008 | SearchSecurityChannel.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

No one wants to simply "detect" intrusions. Everyone, quite rationally, wants to prevent intrusions. Leading up to 2003, IDS vendors claimed ever greater capabilities to detect intrusions, with supposedly lower false positive rates. Customers naturally asked the question, "If you can detect it, why can't you prevent it?" Companies selling so-called "intrusion prevention systems" answered "We can!" and dealt a body blow to the IDS market.

About the author
Richard Bejtlich is director of incident response at General Electric Company in Manassas, Va. and blogs at Bejtlich.net and TaoSecurity.com. Listen to the rest of Richard's answers on Snort by downloading our Snort podcast.

The undeniable fact of the matter, however, is that preventing a network-based intrusion requires detecting it. No one has built, or ever will build, a network-based (or host-based, or anything-else-based) system that performs 100% accurate detection, so that means 100% prevention is also impossible. What should you do with events that are not regarded with 100% confidence as being malicious? If you block them, you could deny legitimate business traffic. The sensible alternative is to alert on them and let a human analyst investigate the situation. Hence, we have returned to seeing IDS as a useful tool. IPS, incidentally, is quickly becoming another feature on the network firewall.

Return to the Snort FAQ guide and read the rest of Richard's expert responses.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Is Snort right for the IDS needs of all clients?
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
What is Snort?
Is Snort right for the IDS needs of all clients?
How does Snort's flavor of intrusion detection work?
What is the difference between Snort and Bro?

Snort
The power of Snort 3.0
When Snort is not enough
Justifying Snort
Network session data analysis with Snort and Argus
How to use shared object rules in Snort
How can the operator test Snort?
How can I learn more about Snort?
Snort limitations
Top five Snort tips
Snort 2.8.0 new features: IPv6 and port lists

Open Source Security Software
Network session data analysis with Snort and Argus
How to use shared object rules in Snort
Is Snort right for the IDS needs of all clients?
What is the difference between Snort and Bro?
Will deploying Snort detect malicious events quickly?
How can the operator test Snort?
How can I learn more about Snort?
What does the future hold for Snort?
What extra functionality do Snort add-ons provide?
Does Snort support target-based intrusion detection?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts