IDS mailing list archives

Re: Is IDS/IPS worthless?


From: Konrad Rieck <kr () roqe org>
Date: Sat, 21 Feb 2004 15:27:55 +0100

On Fri, 2004-02-20 at 17:31, Andrew Plato wrote:
So this speaker then challenged me to come up with verifiable metrics. I
replied that he would have to define what metrics he wants? What does he
consider a "viable metric" for performance.  He said "did they sell more
products, make more money?"  I replied "why is that the only metric that
businesses can understand? 

IT security is about keeping money - not making it. IDS/IPS reduce the
the probability of an undetected compromise. Depending on your setup,
environment and data such a compromise may result in an enormous
financial loss.

The relation between 

   ...the probability of a successful compromise in respect to the 
      resulting costs

and 

   ...the probability for a detection in respect to the maintenance 
      costs of an IDS/IPS solution
 
form a verifiable metric (unless you talk with someone who can't deal
with probabilities).

Here's nice paper on that topic...

   "Cost-Benefit Analysis for Network Intrusion Detection Systems"
   http://www.csds.uidaho.edu/director/costbenefit.pdf 

Regards,
Konrad

-- 
Konrad Rieck <kr () roqe org> ------------ http://people.roqe.org/kr
Fingerprint - 7D55 5896 834A A1C8 303C - 8BC5 4C53 3611 C1FA 82F2

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: