Wouldn a good intrusion detection program eliminate the need for file integrity assurance products?
In theory, yes. However, all current IDSs search for events that cause data change rather than the effects of such change. A cause may or may not result in an intrusion and similarly, an intrusion may occur without alerting the IDS. This is how “false positives” and “false negatives” occur. In contrast, Copperfasten deals with the effects of change rather than the causes so it can always detect an intrusion and can always differentiate between authorized and unauthorized change.