1 Dec 2008 14:43
Re: Host Based IDS
Security Group <secgro <at> gmail.com>
2008-12-01 13:43:29 GMT
2008-12-01 13:43:29 GMT
Hi, First of all many thanks for your replies and excuse me for my late response. Your requests for clarification are justified. I will describe the situation: We have Windows servers (60+) with custom server applications (self developed software) which are in the DMZ. There is already a network based IDS present based on S-flow packets. But since the DMZ is the first base on the way-in by any hacker we want intrusion detection on the machines in the DMZ. We now have a very simple IDS in place which monitors process starts. This HIDS will report an alert if an abnormal process start will occur (i.e. a reverse shell will start cmd.exe in an abnormal fashion). This is only one simple abnormality check on a host. We are wondering if there are other host based IDS which check for abnormal process start and much more (file integrity, event log, etc) . Which HIDS will provide abnormality checking (process starts, event log, file integrity, etc) on a host the best: OSSEC Open Source Tripwire SAMHAIN OSIRIS AIDE Third Brigade Deep Security Symantec Critical System Protection(Continue reading)
RSS Feed