When Prevention Fails: The Role of IPS in Incident Response
Intrusion prevention technology is understandably focused on using network data to detect and to stop intrusions in progress. When (not if) intrusion prevention systems fail to prevent intrusions, can they provide any value to the management of an incident? Using a case study of a security incident that took an international organization offline, we will look at the IPS technology in place, the role that it played in addressing the incident, and how the incident progressed when the IPS failed to achieve its expected objectives. Lessons learned will include consideration of how to use IPS technology can better be deployed, how available data may be used to assess fast-moving situations, and how IPS technology can fit into a larger program for identifying and responding to security incidents.
- Presenting
- C. Matthew Curtin, Interhack, Founder
- Channel
- Information Security
- Date
- Jul 08 2010
- Duration
- 00:46
- Tags
- IPS, Incident response, Security
Flash is required to view this webcast/channel:
You need version 9.0.115.0 or later of the free Flash player from Adobe
to use this content. To download and install the free player from Adobe's web site
click here.


