[Dshield] InMon Corp.'s internal IDS

Mark Tombaugh mtombaugh at alliedcc.com
Thu Apr 29 13:21:49 GMT 2004


On Wednesday 28 April 2004 8:21 am, Pete Cap wrote:
> The InMon corporation has developed an IDS solution which monitors internal
> traffic flow instead of just the perimeter in order to catch worms and
> such.

Sounds like you could do the same thing with Snort + span sessions (monitor 
WAN & LAN) for the low low price of free. Maybe I'm missing something, but I 
don't see anything that "completely revolutionizes the way that the all too 
frequent worm outbreaks are handled" here. 

If you do get it, it would be interesting to deploy it along with snort to see 
the diff.

-- 
Mark Tombaugh <mtombaugh at alliedcc.com>
Allied Computer Corporation <http://www.alliedcc.com>
USiHOST, iNC <http://www.usihost.com>





More information about the list mailing list