TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

A fact you should always keep in mind:
Snort is a barebone IDS - you will have to find a roll-your-own-solution
regarding management, although there are many good tools for management and
analysis (ACID, PureSecure, IDSCenter, BigBrother plugins, IDS Policymanager,
webmin plugins etc.)

ISS is a commercial _solution_ , i.e. it provides analysis, management and
corellation and
a tiered architecture for enterprise-wide deployment.

IMHO, this exactly is the surplus value of a commercial solution.

The only reasonable comparison would be between the commercial snort
solution of 
sourcefire and RealSecure.

Me personally, I would use both systems - ISS for enterprise-wide deployment
and snort
as a complementary IDS. 

I haven't tested sourcefires solution, yet.
This would be very interesting, too.

HTH,
Detmar


>2002-07-31-13:34:07 Simon Desmeules:
>> Good stuff, have you received any technical documents that compare
>> Real Secure vs Snort?  If so, I`d like to take a look at it.
>
>No, I've not received any such material.
>
>As the products are rather different, and as each product is
>evolving very rapidly, and not always in the same directions, such
>comparisons are awfully hard to do except at the very most
>superficial level. It's safe to say that Snort is open source and
>Real Secure is not. From that certain other conclusions may follow.
>Just about any detail beyond that would be very version-specific and
>time-limited.
>
>-Bennett


-- 
GMX - Die Kommunikationsplattform im Internet.
http://www.gmx.net



Reply via email to