A useful oversimplification for network surveillance?

Florian Weimer fw at deneb.enyo.de
Thu Aug 25 16:06:52 UTC 2005


> I'd most certainly use an IDS (i.e. SNORT) for this instead of
> netfow....

Could you provide a use case at the ISP level where an IDS is indeed
superior to NetFlow data collection?

(Take into account that ISPs typically see the effects of new malware
well before the AV companies. 8-)



More information about the NANOG mailing list