Writing Assignment: Module 07 Real-World Flashcards
Do a Web search for open source and freeware intrusion detection tools. Identify a commercial equivalent of one of the no-cost choices. What would the estimated cost savings be for an organization to use the open source or freeware versions? What other expenses would the organization need to incur to implement this solution?
https://www.snort.org/
a commercial equivalent of Snort is Cisco Firepower. Cisco Firepower is a network security solution that includes intrusion detection and prevention capabilities, similar to Snort.
The estimated cost savings for an organization to use Snort instead of Cisco Firepower would depend on the size and complexity of the network and the number of licenses needed. However, in general, Snort is free to use and can result in significant cost savings for organizations compared to commercial solutions.
other expenses are
Hardware requirements
Training
Support
Integration
Find out more about defense in depth. Visit youtube.com and search for “network defense in depth.” Select one or two of the options and watch the videos. What is the primary value or justification for using this approach?
Having multiple layers makes it so if one fails you have another to back it up and continue protecting.
Don’t rely on one security to protect your system.
Visit the site www.honeynet.org. What is this Web site, and what does it offer the information security professional? Visit the “Know Your Enemy” white paper series and select a paper based on the recommendation of your professor. Read it and prepare a short overview for your class.
www.honeynet.org is the official website of The Honeynet Project, a non-profit organization that aims to improve the security on the Internet by developing open-source technologies, methodologies, and tools to study, detect, and counteract computer attacks.
The website offters research papers, tools, and vast community of volunteers and researchers who work together to improve computer security.
The OSSIM product from AT&T Security (formerly AlienVault) offers an interesting and useful online demonstration version you can use to learn more about SIEM tools. After you try the demo, the company offers the open source SIEM tool for downloading. You can access the online demo of the USM Anywhere application at https://cybersecurity.att.com/products/usm-anywhere/demo.