What Are Intrusion Detection Systems (IDS)?
by Fred Avolio, Avolio Consulting, Inc. “Just a moment… just a moment… I’ve just picked up a fault in the AE-35 unit. It’s going to go one hundred percent failure within seventy-two hours.” Science fiction buffs (and only old ones at that, as I’ve discovered) will remember this quote uttered by “the sixth member of the crew” of spaceship Discovery in the 1968 movie, 2001: A Space Odyssey. The speaker was, of course, the HAL 9000 computer, a self-described “conscious entity.” First, the bad news: IDS products are not that smart. They do not employ artificial intelligence. They do not provide an impenetrable barrier, nor can they read user motivation. Now, the good news: IDS can be useful additions to security defenses, anyway. In an article published in Internet World, March 22, 1999, Dave Piscitello and I wrote, “When mainframes were the mainstay of computing, we encased them in glass houses. Locked doors and security badges were sufficient … In a world where the network is more