|
|
Article: Guidelines for would-be corporate vigilantes.(network intrusion detection systems)(Technology Information)
- Article from:
- Network World
- Article date:
- January 11, 1999
- Author:
CopyrightCOPYRIGHT 1999 Network World, Inc. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan. All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)
|
There are many ways to detect break-ins and a variety of options on how to proceed once you do. Here's a collection of insights from dozens of users, analysts and vendors on the techniques that work best.
Use quality detection systems. You want to detect miscreant insider behavior as well as external hacking. Host-based auditing, network behavior statistics and traffic analysis are all good sources of security-related data that can alert you to abnormalities that may indicate a security incident. Keep in mind that intrusion detection systems (IDS) are all a little different. Some excel in NT, others in Unix or Novell, and some pick up anomalies and events that ...