Quote:
That's where IDS's come in handy. If he's going to make a mistake it will probably be in the early stages of the footprinting phase when he may unleash a scan that is just noisy enough to alert the IDS. Now you can track the activity from that subnet to see what is happening. The benefit here is the pre-warning that something is about to occur. Even if he blasts away in a few seconds, finds an exploitable service, exploits it and cleans the system of evidence when you come in in the morning the warning that something occured should still be on your IDS. Even if you can't find any other evidence you can watch the box to see what happens when they come back next time and then you will have a clue as to what to do to re-protect the box.
Since the hackers once break into your system,he can still clean up his log files in the access log and why can't he clean up his access log for the IDS?Since he can able to clean up his access log and i do not see the point that he cannot clean up his log for IDS too.