Detection and prevention: 6 intrusion detection systems tested

Specifications

Product CA eTRUST Intrusion Detection 3.0 Juniper IDP McAfee Intrushield I-series
Vendor Computer Associates Juniper McAfee
Phone 02 9937 0500 02 8913 9800 1800 644 646
Web www.ca.com www.juniper.net www.mcafee.com.au
RRP (as tested inc GST) AU$3639 for 125 sessions IDP100 AU$29,990 I-1200 AU$19,633.93
Warranty Maintenance Licences include free support for 12 months 1 year hardware/software, can be extended to 3 years One year, renewable annual as part of support agreement
Real-time traffic analysis Yes Yes Yes
Virus/worm/trojan detection Yes Yes Yes
External attack detection Yes Yes Yes
Internal attack detection Yes Yes Yes
Attack blocking capability Yes Yes Yes
External probe detection Yes Yes Yes
Internal probe detection Yes Yes Yes
Probe blocking capability Yes Yes Yes
Blocking definitions Yes Stateful signatures, protocol anomaly, backdoor detection, traffic anomaly, layer 2 protection, syn flood, enterprise security profiler Updates, user-defined block lists and customisable rules
Real time alerting E-mail, pager, run application, SNMP, console Email, syslog, snmp, logfile, SMS-external Console, e-mail, pagers, SMS via e-mail
Data packet logging Workspace (proprietary), ODBC database Syslog, internal database Oracle, MySQL
Content searching Yes Yes N/A
Content matching Yes Yes N/A
Content filtering Yes Yes N/A
Filtering methods URL database Admin definied N/A
Reporting tools Yes Yes Yes
Operating system support Windows 2000 (standalone) Windows 2000/2003/XP for Remote Engine Management console Windows, Linux; Management server Linux, Solaris Management console Windows 2000
       

Product McAfee Entercept 5.0 Snort 2.1.3 SonicWALL IPS service
Vendor McAfee Snort ACA Pacific
Phone 1800 644 646 +410 423 1901 03 9674 8188
Web www.mcafee.com.au www.snort.org www.sonicwall.com
RRP (as tested inc GST) Management server AU$8920, Windows Server agent AU$1730, desktop agent AU$37 Free under the GNU General Public Licence TZ170 US$595 to PRO5060 US$14,950
Warranty One year, renewable annual as part of support agreement No warranty provided 1 year included, extended warranty/available
Real-time traffic analysis Yes Yes Yes
Virus/worm/trojan detection Yes Yes Yes
External attack detection Yes Yes Yes
Internal attack detection Yes Yes Yes
Attack blocking capability Yes Yes Yes
External probe detection Yes Yes Yes
Internal probe detection Yes Yes Yes
Probe blocking capability Yes Yes Yes
Blocking definitions Updates, user-defined block lists and customisable rules Updates, third-party integration, user customisable Updates
Real time alerting Console, e-mail, pagers, SNMP, process spawning Logs, e-mail, console, third-party applications Logs, e-mail, syslog, SGMS
Data packet logging Microsoft SQL Server N/A N/A
Content searching N/A Yes Yes
Content matching N/A Yes Yes
Content filtering N/A Yes Yes
Filtering methods N/A Admin defined Blacklist, third party, admin defined
Reporting tools Yes N/A (sold separately) N/A (sold separately)
Operating system support Management system Windows 2000; console Windows NT, 2000, XP; agents Windows, Solaris, HP/UX Linux, Windows Any IP environment
       

Advertisement

Talkback 0 comments

Back to top

Featured