Network-Based IDS Buyer's Guide

Network-based intrusion detection systems (NIDS) monitor network traffic for signs of attack. Before you purchase a solution, make sure you ask your vendor about these 10 critical issues.

  1. Detection methodology: Does the system use signature-based, anomaly-based, or behavioral detection? Most modern solutions combine multiple approaches.
  2. Signature update frequency: How often are signatures updated? Is the update process automatic?
  3. Performance under load: What happens when the sensor is overloaded? Does it drop packets or log an alert?
  4. False positive rate: Ask for data on false positive rates in environments similar to yours.
  5. Encrypted traffic: Can the sensor analyze encrypted traffic? If so, how?
  6. IPv6 support: Does the solution fully support IPv6 traffic analysis?
  7. Management console: Is a centralized management console included? What does it cost?
  8. Logging and reporting: What logging capabilities are included? Does it integrate with your SIEM?
  9. Hardware options: What hardware platforms are available? Is a software-only option available for virtual environments?
  10. Support and updates: What is the support SLA? How are updates delivered?
Related Content
The Definitive Guide to Network Security

9 checklists for securing your network.

IDPS Buyer’s Checklist

Questions to ask before purchasing an IDPS.