Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

Intrusion Detection System

Here you can discuss every aspect of Debian. Note: not for support requests!
Post Reply
Message
Author
Burner
Posts: 4
Joined: 2007-03-21 12:16

Intrusion Detection System

#1 Post by Burner »

Hello all GNU/Linux users.

I'm a student and I'm doing an research about Open Source Host Intrusion Detection Systems and usability.

The work is almost done but I also want to do an quick(9 questions) survey online so I can compare it with my result.

The paper is limited to open source intrusion detection systems.

Please take a minute and make an contribution to this paper if your are using or have been using any system below.

*FCheck
*serverM
*AIDE
*Swatch

http://www.thegate.nu/idssurvey/

Thanks.

---------------------------------------
Debian user since -97

User avatar
hcgtv
Posts: 500
Joined: 2006-11-17 23:03
Location: Charlotte, NC

#2 Post by hcgtv »

What happened to Snort?

http://www.snort.org/
Bert Garcia - When all you have is a keyboard

Burner
Posts: 4
Joined: 2007-03-21 12:16

#3 Post by Burner »

hcgtv wrote:What happened to Snort?

http://www.snort.org/
Snort is an NIDS and not HIDS.

Both NIDS and HIDS has pros and cons.

User avatar
hcgtv
Posts: 500
Joined: 2006-11-17 23:03
Location: Charlotte, NC

#4 Post by hcgtv »

Burner wrote:Snort is an NIDS and not HIDS.
Oh, ok I see.

So you're going after file changes, etc. Not so much how they enter.
Bert Garcia - When all you have is a keyboard

Burner
Posts: 4
Joined: 2007-03-21 12:16

#5 Post by Burner »

hcgtv wrote:
Burner wrote:Snort is an NIDS and not HIDS.
Oh, ok I see.

So you're going after file changes, etc. Not so much how they enter.
Right, HIDS can detect intrusions from the inside like:

*Backdoors
*New illegal users added
*Rootkit detection
*New services started
*Logfile analysing, like SSH bruteforce attacks

and a lot more.


Burner
Posts: 4
Joined: 2007-03-21 12:16

#7 Post by Burner »

I have been using Tripwire before, but the I started to use FCheck. It does almost the same things.

The best IDS I have been using is LIDS(Linux Intrusion Detection System)

Combine LIDS with an tight configuration and serverM or Swatch, then you will have a rock solid GNU/Linux system :)

Post Reply