When I teach Network Security Monitoring I often introduce the alternative using an image like the following. It shows what an analyst (here, Elvis) might do if the only data he had to work with as an alert from something like a traditional intrusion detection system.
Compare that workflow with the possibilities provided by Network Security Monitoring:
Usually when I present this concept I take the opportunity to mention that Elvis studied American Kenpo with the founder of the style, Ed Parker. I also mention that Elvis frequently performed karate on stage, even doing so at someone else's concert!
I decided to track down a reference for that particular story, and through Shane Peterson's Elvis and the Martial Arts found this:
Elvis attended the Tom Jones show on September 3rd , during the show he was introduced to the crowd by Tom, at that moment he was invited on stage and Tom asked him if he'd like to sing something, it wasn't possible he said as he had an exclusive contract with the Hilton, so instead he went into a Kata demonstration on the Caesar's Palace stage.
I would prefer to include links to the Web pages where I found these, but since they are hosted on Tripod pages I don't want to kill the owner's bandwidth through unnecessary click-throughs. If you want to find the sources please do a Google search.
Richard Bejtlich is teaching new classes in Las Vegas in 2009. Early Las Vegas registration ends 1 May.