Re-branding IPS as an anti botnet tool
October 24th, 2006 by SecuriTeam, Filed under: Botnets, Networking
i have seen a pr last month from mcafee on this issue, and now they issued another one.
for most cases, i don’t believe in ids products.
i think that trying to pitch i[dp]s as a solution for botnets is technologically silly, but marketing-wise right on the spot. as the solution it is plain and simple silly.
a lot of security vendors will now start taking that approach, dealing with the buzzword.
an ips will not cure your botnet problems. it may help pinpoint some bots (or similar) on your network, which is important, but that’s about it.
i wish mcafee all the luck in the world, but this is, in my opinion, way
way way over-hyped:
http://www.mcafee.com/us/local_content/white_papers/wp_botnet.pdf
in another pr they present a case study on how they saved a south american
country from a botnet attack using their ips. i would like to see
more.. or something, to back it up as to how, before i state my opinion.
what do you think?
gadi evron,
ge@beyondsecurity.com.
-
Dave Reggie
-
Tuffer



