LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-20-2004, 09:20 AM   #1
pnh73
Member
 
Registered: Jul 2003
Location: Birmingham, UK
Distribution: Ubuntu,Debian
Posts: 381

Rep: Reputation: 30
Recommended Host Intrusion Detection System...


I am looking for an reasonably easy to configure, Open Source, Host Intrusion Detection System that I can run on my server. Does anybody have any recommendations, links or information about these?

Thanks in advance
 
Old 09-20-2004, 09:27 PM   #2
m4dj4ck
Member
 
Registered: Aug 2004
Location: the coven
Distribution: slackies
Posts: 55

Rep: Reputation: 15
1. samhain ( http://la-samhna.de/samhain/ )

2. Osiris ( http://osiris.shmoo.com/ )
 
Old 09-21-2004, 03:13 AM   #3
dominant
Member
 
Registered: Jan 2004
Posts: 409

Rep: Reputation: 30
Intresting thread.

Tripwire is a IDS isn't?
 
Old 09-21-2004, 03:49 AM   #4
m4dj4ck
Member
 
Registered: Aug 2004
Location: the coven
Distribution: slackies
Posts: 55

Rep: Reputation: 15
no. it is not. tripwire is not an IDS. it acts like aide, another open source file intregrity checker. it checks for changes in files/binaries/etc. tripwire is older than aide. aide is the improvement/replacement for tripwire.
 
Old 09-21-2004, 04:11 AM   #5
dominant
Member
 
Registered: Jan 2004
Posts: 409

Rep: Reputation: 30
any reference for the aide?
 
Old 09-21-2004, 05:05 AM   #6
m4dj4ck
Member
 
Registered: Aug 2004
Location: the coven
Distribution: slackies
Posts: 55

Rep: Reputation: 15
www.cs.tut.fi/~rammer/aide.html
 
Old 09-21-2004, 06:25 AM   #7
dominant
Member
 
Registered: Jan 2004
Posts: 409

Rep: Reputation: 30
I can see very slow improvements

aide - 0.10 - November 27, 2003
 
Old 09-21-2004, 11:21 AM   #8
pnh73
Member
 
Registered: Jul 2003
Location: Birmingham, UK
Distribution: Ubuntu,Debian
Posts: 381

Original Poster
Rep: Reputation: 30
Thanks for your replies.
Samhain looks like the best bet for me at the moment. I like the security that is inbuilt into its logs and processes.

I am also looking for a system that can temporarily block IP's that are misbehaving, such as the SSH username attack that I am getting everyday and have quite a large list of IP's that are being now being blocked by the servers firewall (iptables/ipchains).

This list grows by the day and I was wondering if there is anything that I can implement to automatically detect these attacks and port scans on a host and then block the IP for a set time or something?

Thanks again
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
intrusion detection system aparna Linux - General 4 01-02-2006 09:30 AM
intrusion detection system aparna Linux - General 2 12-31-2005 01:03 AM
Intrusion Detection System On Linux AmitC Linux - Networking 1 10-19-2004 03:34 AM
Network Intrusion Detection System WarlockofVirgo Linux - Security 1 08-08-2004 10:36 PM
Intrusion Detection System (ids) Stormproof Linux - Security 7 08-22-2002 08:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration