9/4 Has anyone here played with commercial security monitoring/scanning
apps? I'm looking at Eeye, ISS, and Axent NetRecon for host-based
monitoring and host/network scanning, and Cisco Netranger/NFR/
Netprowler/Eeye for IDS--I'd appreciate any experiences people would
care to share about any of these. -John
\- the all suck to various degrees. the people who want to
sell you stuff worry more about "sexy features" like drawing
useless graphs and html reports rather than working on actually
hard problems. they may be ok for MIS-types but hackers should
use bro. also, what speed are you monitoring? unclear who
can keep up with 100mbit full duplex. --psb
\_ It's more a matter of being able to show due diligence
to govt. and investment inspector types who bring along
their pet MIS guy and who may have heard this or that about
commercial implementations. I see the limitations of
most commercial products I've looked at, but I need to
find the "least worst" in addition to whatever "real"
IDS and system/network hardening I'm doing. -John |