Make the most of your IDS by beefing up your incident reports
Once the IDS alerts you to something going on, the typical response might be to call or e-mail an administrator to impart this information. But before you make the call or send the e-mail, take a minute to consider how best to present the information. You need to find a way to translate this report into detailed information and actionable suggestions that will help defend your company's network from hostile attacks.For example, you could say something like, "We're seeing an SMB service sweep coming from 10.100.64. 10 and BitTorrent activity from 10.100.55. 23." However, while this information might seem useful to you, it has little or no value when it comes to the administrator who has to take action on your report.
- Add new comment
- 1688 reads

Recent comments
16 weeks 6 days ago
37 weeks 4 days ago
40 weeks 2 days ago
40 weeks 2 days ago
44 weeks 5 days ago
44 weeks 6 days ago
1 year 9 weeks ago
1 year 12 weeks ago
1 year 15 weeks ago
1 year 27 weeks ago