000000154 100__ $$aRodrigo Werlinger
000000154 245__ $$aThe Challenges of Using an Intrusion Detection System: Is It Worth the Effort?
000000154 260__ $$c2007-06-13
000000154 520__ $$aAn intrusion detection system (IDS) can be a key component of security incident response within organizations. Traditionally, intrusion detection research has focused on improving the accuracy of IDSs, but recent work has recognized the need to support the security practitioners who receive the IDS alarms and investigate suspected incidents. To examine the challenges associated with deploying and maintaining an IDS, we analyzed 9 interviews with IT security practitioners who have worked with IDSs and performed participatory observations in an organization deploying a network IDS. We had three main research questions: (1) What do security practitioners expect from an IDS?; (2) What difficulties do they encounter when installing and configuring an IDS?; and (3) How can the usability of an IDS be improved? Our analysis reveals both positive and negative perceptions that security practitioners have for IDSs, as well as several issues encountered during the initial stages of IDS deployment. In particular, practitioners found it difficult to decide where to place the IDS and how to best configure it for use within a distributed environment with multiple stakeholders. We provide recommendations for tool support to help mitigate these challenges and reduce the effort of introducing an IDS within an organization.
000000154 6531_ $$aIntrusion Detection
000000154 6531_ $$aUsable Security
000000154 6531_ $$aCollaboration
000000154 6531_ $$aQualitative Research
000000154 6531_ $$aSecurity Tools
000000154 6531_ $$aOrganizational Factors
000000154 6531_ $$aHOT Admin
000000154 6531_ $$aissnet
000000154 700__ $$aKirstie Hawkey
000000154 700__ $$aKasia Muldner
000000154 700__ $$aPooya Jaferian
000000154 700__ $$aKonstantin Beznosov
