Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Network Intrusion Detection, Third Edition.pdf
Скачиваний:
212
Добавлен:
15.03.2015
Размер:
2.58 Mб
Скачать

return when they ask whether you have a firewall, nod when you say "yes," and then walk away.

I think the emerging trend is for auditors to understand security-assessment tools and to be able to operate them. Auditors can visit your site, plug in, and, while they are interviewing you, run an assessment tool. They can then compare your answers against the assessment—cheerful thought, eh?

Although it will be a pain for system administrators when we are audited, knowledgeable, equipped auditors could be one of the most effective countermeasures against the increasing threat. Hackers, trusted insiders, and malicious code authors are not really that smart; we are just a bit lazy, careless, and naive. So when we make a mistake or get sloppy, it leaves a hole that attackers find and exploit. If we are held accountable, we actually do the things that we know we ought to do and the organization benefits.

Summary

All data that I have indicates that the future looks good for the intrusion-detection analyst. We will have plenty of work to do, and we should be able to get decent pay for our work. Good analysts are in extreme demand, and that should not change in the near term. Companies are starting to understand that the skills component is important and are asking for GCIA certifications, or demonstrated ability for higher paying jobs. Tools, techniques, and training are being developed to counter the threats, and some of these will make our lives easier.

Thank you for reading this book. I have enjoyed teaming with Judy and Marty on this update, and I thank them for their skills and insights. Truly this is becoming an analyst's handbook. Please grant me one closing note, one more minute of your precious time. The www.incidents.org resource depends upon the involvement of the community and may well have to close at some point. While it is there, your book comes with a warranty, a way to stay up-to-date, a forum to discuss anything you don't understand or disagree with, and most important, a place for you to share your insights. Please get involved. We welcome every nation, every point of view, and detects from every brand of intrusion-detection software. Intrusion detection is in its infancy and needs to improve. That can only happen if you get involved. See you on Incidents!

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]