Thursday, February 7, 2008

WSJ - Don't Fence Me In

IDS (Intrusion Detection Systems) are becoming more popular for businesess as they worry about the security of their data. These systems certainly have their place in business and the article mentioned the financial losses from cybercrime. I am sure that for the 1 company that reports cybercrime, there are 10 companies that don't. Cybercrime can destroy a business and I think coupling this technology with other technologies such as firewalls and other access controls is a must for every businesses. But, because all of these things put overhead on the network (including AV and other host based scanners) and speed will always be a tradeoff until processing capabilities can be improved.

False positives is and will always be an issue because the enviroment in which it monitors is so dynamic. I think education of users as to the dangers out on the web and how to protect yourself and the company can help eliminate many issues associated with IDS. Companies should also invest a good portion of the money for an IDS into the setup and maintenance. These systems are complicated to administer and become easily outdated without regular and routine maintenance.

No comments: