Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Development
    • Development

    Tool Aims to Reduce IDS False Alarms

    Written by

    Dennis Fisher
    Published May 2, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      As administrators and IT managers continue to look for ways to improve the signal-to-noise ratio in their IDS systems, a small Indiana company is unveiling a new product designed to reduce false positives and get fixes to vulnerable machines quickly.

      Intelligent IDS combines the functionality of a typical network IDS with real-time vulnerability assessment and remediation capabilities. Taken individually, none of these features is exactly groundbreaking. But Intelligent IDS is one of the first products to throw them all in the same mix.

      The new software is essentially a plug-in for the Snort open-source IDS and also uses the Nessus open-source scanner.

      The most oft-voiced complaint about IDS technology is its propensity for false alarms. A security specialist managing an IDS at any medium or large enterprise is likely to spend a great deal of time sorting through page after page of logs filled with seemingly important attacks, only to find that the vast majority of these events are the electronic equivalent of those expensive and annoying car alarms that everyone ignores. SecurityProfiling Inc. officials say their technology will help reduce the number of false positives by comparing incoming attacks against the configuration of the besieged machine to see whether it is vulnerable to that particular exploit.

      This is accomplished by taking the signature of the attack and its destination IP address and running them through the softwares logic engine. Intrusion attempts against vulnerable machines are logged as incidents and the administrator is notified and given the option of installing the patch for the vulnerability in question. Attacks against secured machines are simply logged as events.

      Administrators can install patches remotely and will also get detailed reports on what changes were made to the machine. Company officials say they see Intelligent IDS as separate from the mass of security event management products on the market.

      “That may be successful for some organizations, but our philosophy is fundamentally different,” said Brett Oliphant, CTO and founder of SecurityProfiling, based in Lafayette, Ind. “We dont use vulnerability assessments because if that worked, youd already know your machine was vulnerable and have it fixed.”

      Instead, the software looks at each machines configuration to see whether the current attack will succeed against it.

      Other companies, most notably Citadel Security Software Inc., are pursuing similar paths. However, Citadels Hercules software is meant more for automated vulnerability assessment and remediation and does not include integration with an IDS.

      SecurityProfiling plans to add several other components to the system, starting with a firewall and a scanner. Version 2.0 of Intelligent IDS is due in late June, Oliphant said. Version 1.0 is available now for a $4,995 license fee.

      Latest Security News:

      Search for more stories by Dennis Fisher.
      Find white papers on security.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×