Re: OSSIM as IDS
dogten <[email protected]>
| Newsgroups | gmane.comp.security.ids |
|---|---|
| Message-ID | <[email protected]> |
Tremaine Lea wrote: > Unfortunately, that's true of most IDS worth the name. Whether one is > looking at Tipping Point, Sourcefire or another commercial offering, > you're looking at a pretty good investment of time. > > > --- > Tremaine Lea > Network Security Consultant > Intrepid ACL > "Paranoia for hire" > > > > On 21-May-08, at 10:21 AM, [email protected] wrote: > >> Good, but a lot of work to get it in place. >> David >> >> Quoting [email protected]: >> >>> Dear All, >>> >>> Is that anyone has worked on OSSIM as an open source for intrusion >>> detection? >>> >>> Regards >>> Preeti We had a bad experience with OSSIM on high load networks, too many bells and whistles. EasyIDS seems to be a better fit for us and comes with wizard based configuration for Barnyard integration. -- -dogten http://blog.memoryoffset.com "I have not failed. I've just found 10,000 ways that won't work." - Thomas Alva Edison (1847-1931) ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------