Make the most of your IDS by beefing up your incident reports
Once the IDS alerts you to something going on, the typical response might be to call or e-mail an administrator to impart this information. But before you make the call or send the e-mail, take a minute to consider how best to present the information. You need to find a way to translate this report into detailed information and actionable suggestions that will help defend your company's network from hostile attacks.For example, you could say something like, "We're seeing an SMB service sweep coming from 10.100.64. 10 and BitTorrent activity from 10.100.55. 23." However, while this information might seem useful to you, it has little or no value when it comes to the administrator who has to take action on your report.
- Add new comment
- 1268 reads

Recent comments
2 weeks 4 days ago
2 weeks 5 days ago
25 weeks 5 days ago
28 weeks 3 days ago
32 weeks 3 days ago
32 weeks 4 days ago
37 weeks 4 days ago
39 weeks 3 days ago
40 weeks 23 hours ago
40 weeks 3 days ago