

Intrusion Detection Systems for Gigabit Networks? 11
caelyx asks: "I've got to evaluate various IDS solutions for use on a gigabit network. While I've had experience using and configuring snort, I haven't used many of the commercial solutions (Dragon, RealSecure, ManHunt, etc). I guess I'm mostly concerned with signature quality and depth, the power of the analysis console(s) and a robust engine that won't drop packets on a busy network. What experiences have Slashdot readers had with various NIDS or hybrid NIDS/HIDS solutions? Suggestions?" Ask Slashdot last touched this topic in this discussion, but it didn't focus on the needs for a Gigabit network. How well do the solutions mentioned therein perform on such a high end network?
Snort! Sourcefire sells gigabit systems (Score:4, Informative)
Dragon (Score:4, Informative)
I'd expect FreeBSD would also have good performance, but they didn't produce a 6.0.1 build for FreeBSD (they told me its around the corner, but theres not much demand for it. I'm running the Solaris variant at work)
Ultimately, I'd say contact Enterasys and ISS with you're needs and ask for a demo license. Everyones situations are different. You may decide snort fits you're needs, or you may need something else.
intrusion.com (Score:3, Informative)
Check out Arbor Networks, (Score:3, Interesting)
More info here [arbornetworks.com].
Don't use Guardent (Score:3, Informative)
Comment removed (Score:3, Informative)
Manhunt (Score:2, Informative)
review (Score:2)
What about Counterpane? (Score:1)
Their prices [counterpane.com] aren't bad; you could easily justify them.
(You can read their case studies here [counterpane.com])
ISS (Score:2)