Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: !LEM Thoughts of the Week: Detecting the Target Breach?

$
0
0

I actually have the book Tao of Network Security Monitoring sitting on my desk though have actually read very little of it... its on the list.

 

I took a look at that beta for DPI that you linked to; however, it didn't look at all like what I would have expected.  I guess when I am talking about packet inspection I am thinking something more like the product HERE.  The DPI beta looked more like additional features that would be included as part of NTA.

 

When we turn our firewalls logging up I can see every accept and deny that takes place so the data is pretty granular.  While I can certainly see value in a Packet Inspector, it seems like you are hitting a point of diminishing returns considering the cost to have something like that in place to capture everything you could potentially need.  Maybe I need to spend some more time reading that book. 


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>