Pre IDS Implementation Check List for Sig Tuning
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-14-2005 04:30 AM - edited 03-10-2019 01:45 AM
Hi Experts,
IDS signature tuning can get quite involved.
To make sure nothing important is overlooked, is there a Check List that can be used?
If not, what are some of the critical items that should be known beforehand?
A couple items are obvious e.g. type of OS's used and what servers must never be blocked. But, I'm sure there's a whole list of things that should be considered.
Any feedback would be greatly appreciated.
- Labels:
-
IPS and IDS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-18-2005 07:37 AM
Knowing the behavior of your network and the applications that you are running is very important before signatures can be tuned. To avoid false positive alarms, you may have to observe your network for a while and tune the signatures until you get the desired result. From my experience, signature tuning is a contnious process and has to be monitored on a regular basis.
