<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Discussion on LinkedIn Group: What is the best IDS system?</title>
	<atom:link href="http://blog.ismaelvalenzuela.com/2008/10/13/discussion-on-linkedin-group-what-is-the-best-ids-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ismaelvalenzuela.com/2008/10/13/discussion-on-linkedin-group-what-is-the-best-ids-system/</link>
	<description>on ismaelvalenzuela.com</description>
	<lastBuildDate>Tue, 26 Jan 2010 17:57:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Antonio Maña</title>
		<link>http://blog.ismaelvalenzuela.com/2008/10/13/discussion-on-linkedin-group-what-is-the-best-ids-system/comment-page-1/#comment-1590</link>
		<dc:creator>Antonio Maña</dc:creator>
		<pubDate>Tue, 06 Jan 2009 12:02:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=58#comment-1590</guid>
		<description>Interesting post. Actually, I tend to coincide with both views. 
On the one hand I believe that IDSs as they are today are obsolete and will not be useful to cope with the needs of the next wave of highly distributed systems.
On the other hand, I also believe that the concept will always be valid, as we must assume that we can not build perfectly secure systems. But the new IDSs will have to evolve a lot in order to adapt to the future computing models. In particular, I believe that the way to go is to create micro-IDSs. These IDSs (call them transparency and monitoring capabilities if you want) will have to be integrated in every security-relevant component of the system and they will have to interoperate with the IDSs of other components. The reason for this approach is to maintain the right degree of trust in every component. Transparency in this context means that components expose some of the monitoring results to the rest of the system. In this way an application based for instance on web services can establish a general IDS based on the components&#039; exposed information.

Best regards and btw happy 2009 to all,
Antonio.</description>
		<content:encoded><![CDATA[<p>Interesting post. Actually, I tend to coincide with both views.<br />
On the one hand I believe that IDSs as they are today are obsolete and will not be useful to cope with the needs of the next wave of highly distributed systems.<br />
On the other hand, I also believe that the concept will always be valid, as we must assume that we can not build perfectly secure systems. But the new IDSs will have to evolve a lot in order to adapt to the future computing models. In particular, I believe that the way to go is to create micro-IDSs. These IDSs (call them transparency and monitoring capabilities if you want) will have to be integrated in every security-relevant component of the system and they will have to interoperate with the IDSs of other components. The reason for this approach is to maintain the right degree of trust in every component. Transparency in this context means that components expose some of the monitoring results to the rest of the system. In this way an application based for instance on web services can establish a general IDS based on the components&#8217; exposed information.</p>
<p>Best regards and btw happy 2009 to all,<br />
Antonio.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martijn van Halen</title>
		<link>http://blog.ismaelvalenzuela.com/2008/10/13/discussion-on-linkedin-group-what-is-the-best-ids-system/comment-page-1/#comment-1241</link>
		<dc:creator>Martijn van Halen</dc:creator>
		<pubDate>Tue, 25 Nov 2008 22:17:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=58#comment-1241</guid>
		<description>Nice post Ismael. In my area, online Credit Card payments IDS can be obligated by a security auditor. Some say you will need it some say host based intrusion dection is enough. 
I believe that if you use it, you should watch it 24/7 365. Otherwise it&#039;s a waste of money/time. In that aspect I would suggest a MSSP like BT INS with the http://bt.counterpane.com/ Counterpane solution. Or having your own team of tech support watching. But they need to be trained properly.</description>
		<content:encoded><![CDATA[<p>Nice post Ismael. In my area, online Credit Card payments IDS can be obligated by a security auditor. Some say you will need it some say host based intrusion dection is enough.<br />
I believe that if you use it, you should watch it 24/7 365. Otherwise it&#8217;s a waste of money/time. In that aspect I would suggest a MSSP like BT INS with the <a href="http://bt.counterpane.com/" rel="nofollow">http://bt.counterpane.com/</a> Counterpane solution. Or having your own team of tech support watching. But they need to be trained properly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ismael Valenzuela</title>
		<link>http://blog.ismaelvalenzuela.com/2008/10/13/discussion-on-linkedin-group-what-is-the-best-ids-system/comment-page-1/#comment-404</link>
		<dc:creator>Ismael Valenzuela</dc:creator>
		<pubDate>Tue, 14 Oct 2008 19:51:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=58#comment-404</guid>
		<description>Thanks for your comment Sam.</description>
		<content:encoded><![CDATA[<p>Thanks for your comment Sam.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Van Ryder</title>
		<link>http://blog.ismaelvalenzuela.com/2008/10/13/discussion-on-linkedin-group-what-is-the-best-ids-system/comment-page-1/#comment-403</link>
		<dc:creator>Sam Van Ryder</dc:creator>
		<pubDate>Tue, 14 Oct 2008 18:29:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=58#comment-403</guid>
		<description>You are absolutely right. And this &quot;IDS is dead&quot; argument is actually what has been obsolete for the past few years. If it weren&#039;t the case, we wouldn&#039;t be seeing the growth we are (in my case, an IDS/VA solution provider). It all comes down to what you already describe - the customer&#039;s needs.</description>
		<content:encoded><![CDATA[<p>You are absolutely right. And this &#8220;IDS is dead&#8221; argument is actually what has been obsolete for the past few years. If it weren&#8217;t the case, we wouldn&#8217;t be seeing the growth we are (in my case, an IDS/VA solution provider). It all comes down to what you already describe &#8211; the customer&#8217;s needs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
