LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-19-2007, 02:20 PM   #1
FredrikN
Member
 
Registered: Nov 2001
Location: Sweden
Distribution: GNU/Linux since -97
Posts: 149

Rep: Reputation: 15
Intrusion Detection System


Hello all GNU/Linux users.

I'm a student and I'm doing an research about Open Source Host Intrusion Detection Systems and usability.

The work is almost done but I also want to do an quick(9 questions) survey online so I can compare it with my result.

The paper is limited to open source intrusion detection systems.

Please take a minute and make an contribution to this paper if your are using or have been using any system below.

*FCheck
*serverM
*AIDE
*Swatch

Thanks.


http://www.thegate.nu/idssurvey/

Last edited by FredrikN; 03-19-2007 at 05:06 PM.
 
Old 03-19-2007, 02:49 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
How can anyone contribute when http traffic is filtered on thegate.nu?

edit2:
Code:
[hector@troy ~]$ host thegate.nu
thegate.nu has address 208.69.32.130
thegate.nu mail is handled by 10 www.thegate.nu.
thegate.nu mail is handled by 10 mail.thegate.nu.

[hector@troy ~]$ host www.thegate.nu
www.thegate.nu has address 83.253.117.18

[hector@troy ~]$ nmap -P0 208.69.32.13 -p 80

Starting Nmap 4.20 ( http://insecure.org ) at 2007-03-19 14:54 CDT
Interesting ports on bld3.ash.opendns.com (208.69.32.13):
PORT   STATE  SERVICE
80/tcp closed http

Nmap finished: 1 IP address (1 host up) scanned in 0.190 seconds

[hector@troy ~]$ nmap -P0 83.253.117.18 -p 80

Starting Nmap 4.20 ( http://insecure.org ) at 2007-03-19 14:54 CDT
Interesting ports on c83-253-117-18.bredband.comhem.se (83.253.117.18):
PORT   STATE    SERVICE
80/tcp filtered http

Nmap finished: 1 IP address (1 host up) scanned in 12.061 seconds
I can't access the survey from either. Happy to contribute if you can allow access.

Last edited by anomie; 03-19-2007 at 02:55 PM.
 
Old 03-19-2007, 03:05 PM   #3
FredrikN
Member
 
Registered: Nov 2001
Location: Sweden
Distribution: GNU/Linux since -97
Posts: 149

Original Poster
Rep: Reputation: 15
Hello
Very strange, I'm not blocking anything on port 80.

I'm running Apache and my access.log is full of visitors.

What's your IP ?, maybe there is something wrong with you dns ?

Or maybe problem with my isp

Last edited by FredrikN; 03-19-2007 at 03:18 PM.
 
Old 03-19-2007, 03:19 PM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Maybe your ISP is filtering IPs from Texas.

I think my DNS should be ok - I'm actually using the opendns.com nameservers.

My ISP won't give me information about the DHCP ranges they give out to clients (no matter how much I bother them) but it seems to consist of ranges within a number of class A networks following 66.x.x.x - 71.x.x.x.

Anyway, good luck with your survey. Sorry I can't contribute.
 
Old 03-19-2007, 03:21 PM   #5
FredrikN
Member
 
Registered: Nov 2001
Location: Sweden
Distribution: GNU/Linux since -97
Posts: 149

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by anomie
Maybe your ISP is filtering IPs from Texas.

I think my DNS should be ok - I'm actually using the opendns.com nameservers.

My ISP won't give me information about the DHCP ranges they give out to clients (no matter how much I bother them) but it seems to consist of ranges within a number of class A networks following 66.x.x.x - 71.x.x.x.

Anyway, good luck with your survey. Sorry I can't contribute.
Ok, thanks anyway.
 
Old 03-19-2007, 03:21 PM   #6
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
The site works fine for me, but I haven't used any of those HIDS before so I didn't do the survey.
 
Old 03-19-2007, 03:46 PM   #7
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
You should put "others" in ids because you don't mention tools like samhain for example.
 
Old 03-19-2007, 04:12 PM   #8
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
Quote:
Originally Posted by nx5000
You should put "others" in ids because you don't mention tools like samhain for example.
Yeah I think Samhain and OSSEC are much more popular than some of the other choices too.
 
Old 03-23-2007, 01:54 AM   #9
FredrikN
Member
 
Registered: Nov 2001
Location: Sweden
Distribution: GNU/Linux since -97
Posts: 149

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by nx5000
You should put "others" in ids because you don't mention tools like samhain for example.
Hello. If I make any changes after the survey start it can corrupt the result.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
intrusion detection system aparna Linux - General 4 01-02-2006 09:30 AM
intrusion detection system aparna Linux - General 2 12-31-2005 01:03 AM
Intrusion Detection System On Linux AmitC Linux - Networking 1 10-19-2004 03:34 AM
Network Intrusion Detection System WarlockofVirgo Linux - Security 1 08-08-2004 10:36 PM
Intrusion Detection System (ids) Stormproof Linux - Security 7 08-22-2002 08:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration