Hello All,
We have recently installed an IDS from LanGuard which centralizes security event logs, and amongst other things will alert you when certain categories of event occur.
I would like some tips on is what to actually do when these alerts are triggered. For example if multiple invalid logon attempts during the night trigger an alert, what can I do to stop the intruder in their tracks.
Has anbody come accross any software which would in someway disable the workstation which the events are coming from, or perhaps kill its IP address.
Currently running NT.4 domain. Soon migrating to W2K
Many thanks for any advice
Howard
We have recently installed an IDS from LanGuard which centralizes security event logs, and amongst other things will alert you when certain categories of event occur.
I would like some tips on is what to actually do when these alerts are triggered. For example if multiple invalid logon attempts during the night trigger an alert, what can I do to stop the intruder in their tracks.
Has anbody come accross any software which would in someway disable the workstation which the events are coming from, or perhaps kill its IP address.
Currently running NT.4 domain. Soon migrating to W2K
Many thanks for any advice
Howard