Not Your Father’s IPS: SANS Releases Results On Its Network Security Survey


BETHESDA, Md., Oct. 25, 2013 /PRNewswire-USNewswire/ — SANS announces the results of a new survey sponsored by Hewlett-Packard on network security. In it,

439 survey responses show that IPS is still mainly deployed at the perimeter and is doing a fairly good job at detection, yet only 11% of respondents are turning on IPS to block automatically for 100% of their traffic.

However, 80% are using some automated blocking – a large group (28%) set automatic blocking only for those events they can block with great assurance.

Why aren’t organizations using their IPS automated blocking features more?

Results indicate that respondents want and need more information than their traditional IPS will give them before they can confidently turn on automatic blocking.

Indeed, when respondents laid out their wish lists for a next-generation IPS, 79% say their next-generation IPSs must include more application awareness, 67% want more context awareness, 57% say they need more content awareness, and 56% would like full stack inspection included in their IPS capabilities. This question allowed multiple responses, and this ranking indicates that, above all, respondents want smarter IPS devices that work with a variety of needs.

“Given the industry trend toward simpler and easier interfaces, I was surprised that the overwhelming need expressed in our survey results was for more data,”

says SANS Analyst, Rob Vandenbrink, who authored the report. “They’re also looking for better tools to integrate and process that data.”

To expand their IPS capabilities, respondents are planning to or are already connecting their IPS devices to other security inputs for a next-gen IPS “fabric-oriented” architecture so that their tools, working together, result in better visibility and analytics. This, in turn, not only results in more accurate decisions made on behalf of the IPS, but also offers the ability to feed information back and forth between different security systems for more thorough protection and remediation.

“This survey represents a true ‘slice-of-life’ from real IT shops trying to enhance their IPS capabilities to prevent threats,” adds Vandenbrink.

These and other results will be released during an October 29 webcast at 1 PM EDT hosted by SANS. This webcast is open to the IT community by registering at

The SANS Analyst Program,, is part of the SANS Institute.

About SANS Institute

The SANS Institute was established in 1989 as a cooperative research and education organization. SANS is the most trusted and, by far, the largest source for world-class information security training and security certification in the world, offering over 50 training courses each year. GIAC, an affiliate of the SANS Institute, is a certification body featuring over 25 hands-on, technical certifications in information security. SANS offers a myriad of free resources to the InfoSec community including consensus projects, research reports, and newsletters; it also operates the Internet’s early warning system–the Internet Storm Center. At the heart of SANS are the many security practitioners, representing varied global organizations from corporations to universities, working together to help the entire information security community.


Article source:


Comments are closed.