OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: NetFlow for IDS

From: Jonathan Glass (GMail) (jonathan.glassgmail.com)
Date: Wed Jul 20 2005 - 18:42:28 CDT


Lancope sells a Stealthwatch XE appliance for anomaly-based IDS using
Netflow analysis.

Jonathan Glass

Gary Halleen (ghalleen) wrote:

>That list is handy, but incomplete.
>
>Cisco MARS should be added. MARS is a SIM product that receives log
>information from various sources (firewalls, routers, switches, IDS/IPS,
>host logs, antivirus, and more). It also receives netflow, and can
>provide very useful security-related information based on it.
>
>Gary
>

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------