Multi-layer intrusion detection systems
A business critical system has been breached by attackers. Responding to the event, you grab your gear and head down to where the system is. En route a red faced executive seemingly about to explode brushes past you in a hurry, suddenly turning around upon realization that you are the specialist responding to the very incident which has him on the brink. Already knowing the words about to come out of his mouth, the man begins to spout, "We need this system back up immediately!! We have a major demonstration today and can NOT afford to allow this system to be down! FIX IT NOW!" Politely, you force out a yes sir, and head to the server room where the system is located. As you login, you know time is against you.
Does it take you one hour to get together and analyze the various system logs spread across the system, or do you do this same time consuming task in just a few minutes? That's your choice, and a choice that a multi-layer Intrusion Detection System (mIDS) gives you.
By Nathan Einwechter at SecurityFocus.
[ Read more ]