Is it enough to analyse log files, or is an IDS necessary?
Is it enough to analyse log files or it is necessary (or beneficial) to have an IDS feed to SIM/SEM as well? Will correlated logs provide enough information to pinpoint a security issue or does signature-based IDS provide me with an additional view, which cannot be replaced with just logs?
SearchSecurity.co.UK members gain immediate and unlimited access to breaking UK industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.co.UK today!
Michael S. Mimoso, Editorial Director
In principle, the more data you have to analyse, the better. A good IDS can give you invaluable information about attack types and help put log entries into context. I recommend visiting the
SANS website for some excellent insight into this topic, especially its
Top 5 Essential Log Reports document.
For more information:
A student from Royal Holloway University explains how machine learning can be harnessed to improve many aspects of information security including intrusion detection.
Dig Deeper
-
People who read this also read...
This was first published in October 2009