avatar
c*a
2
there are quite a few artciles talking about nework anomaly based IDS, arbor
networks SP product has been used by some customers, both enterprise and ISP
as IDS device based on netflow stats
others like Juniper ISG2000/1000 with IDP module
Not sure if anyone here have access to BurtonGroup (tbg.com), they have some
interesting articles. Gartner analysis is superficial compared to burton group

,
avatar
z*r
3
I'll try to post another post to conclude the market analysis about IDS/IPS.
I'd like to try a summarization, and fortunately, I've found this,
IDS and IPS are solutions that enhance network security. They should be
implemented as an information infrastructure security level that immediately
follows the firewall. An IDS is a threat and security incident monitoring and
notification solution. An IPS takes additional measures to prevent attacks or
minimise their impact, or actively respond to a sec
avatar
z*r
4
I am not expert of security industry, would like more input from folks here.
But I think DPI is much better than before. More and more companies start
providing hardware based DPI, not just for security, that's for the
applicatoin
networking.
Besides this, I also have concerns about the security rules. Years ago, ppl
don't need to worry about the traffic pattern as for security. However,
enterprises like a all-in-one box to manage the all the access control within
enterprises, say, the p2p traff
avatar
c*a
5
I'm sure Zher will post
but my understanding is that IDS is passive, alert only, and IPS is proactive
and will dynamically put filters on demand
相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。