About 90 % of all alarms from an IDS system is false.
So dont feel safe with it!

/Jonas



-----Original Message-----
From: Martin H Hoz-Salvador [mailto:[EMAIL PROTECTED]]
Sent: den 5 oktober 2000 00:06
To: Jonas Thambert
Cc: '[EMAIL PROTECTED]'; [EMAIL PROTECTED];
[EMAIL PROTECTED]
Subject: Re: [FW1] Testing Firewall-1 [OT]



Jonas Thambert wrote:
> 
> eTrust is a IDS system,
> while ISS is a security scanner.

Anyway, if you have a security (vulnerability) scanner, you may have
"false positives". i.e. Report says that you have a vulnerability where
you don't...   :-(

But the problem is the "technology approach". That's why you still have
to know what  "X" vulnerability is, how to exploit it, and how to patch 
it.

Neither, Vulnerability Scanners or Intrusion Detection Systems are 100%
reliable right now. That's why you still need consultants or analysts to 
intepret results... :-|

B.R.   :-)


============================================================================
====
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
============================================================================
====


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to