Detection and prevention: 6 intrusion detection systems tested

  Detection & prevention
  Computer Assosiates
  Juniper Networks
  McAfee IntruShield
  McAfee Entercept
  Snort
  SonicWALL

 Specifications
 How we tested
 Sample Scenario
 Final words
 Editor's choice
 About RMIT

Final Words
The Computer Associates eTrust Intrusion Detection software provides an excellent IDS platform to log potential threats and intrusions as well as to look at potential internal anomalies that may be occouring on the network. McAfee Entercept 5.0 provides host-based IPS protection and firewall on a host-by-host basis, truly a last point of prevention application which could just save the day. Snort, while a relatively rudimentary IDS, is nonetheless effective; definitely a no-frills system.

The Juniper Networks IDP10 to IDP1000 series provides a range of robust hardware-based IPS options. The McAfee Intrushield I-1200 to I-4000 series of equipment provides IPS functionality, comes with an integrated internal firewall system, and has the ability to virtualise both IPS and internal firewall systems. The SonicWALL range also adds the option of firewall capabilities but can also handle wireless security gateway and management tasks when combined with SonicPoint wireless access points.

Overall these complementary systems provide a very impressive array of equipment for security teams to consider, each with its own nuances. In the right combination, these provide security administrators with a plethora of options and possibilities when trying to track and discover potential vulnerabilities in their network system, before they become gaping holes. The very nature of IT security these days ensures these devices are going to be gaining in popularity over the coming months, so it's worthwhile to spend some time shortlisting and evaluating products to ensure that they slot in to your existing network and security procedures with the minimum of fuss. With so much riding on them, you would have to be crazy not to. And remember, if you're in IT security, never ignore the logs.

This article was first published in Technology & Business magazine.
Click here for subscription information.

Advertisement

Talkback 0 comments

Back to top

Featured