LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-09-2010, 08:37 PM   #1
mike2010
Member
 
Registered: Jan 2009
Posts: 132

Rep: Reputation: 15
Snort or OSSEC ? ( IDS )


It seems like these are the 2 popular ones out there these days..

Trying to figure out which Intrusion Detection System would be best for me.

I've got a CentOs 5 / Linux / Apache system.

If you've got experience with either (or both ) , please let me know your thoughts.

I'm looking for the one thats not as technical, And a bit more user friendly I guess.

Thx

MB
 
Old 01-10-2010, 04:47 PM   #2
esaym
Member
 
Registered: Nov 2006
Distribution: Lots of Debian
Posts: 165

Rep: Reputation: 32
I just used psad because I only wanted to block people that port scan
snort, just takes too much time for me to eliminate false positives. Plus it only alerts, not block

http://cipherdyne.org/psad/
 
Old 01-10-2010, 05:53 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by esaym View Post
I just used psad because I only wanted to block people that port scan
Depending on the purpose of the machine (given the OP runs Apache) just portscans may be the least of his worries.


Quote:
Originally Posted by esaym View Post
snort, just takes too much time for me to eliminate false positives. Plus it only alerts, not block
A little tweaking of the config and rulesets (and maybe a threshold or BPF filter) can help. For blocking with "regular" Snort there's third party apps like Guardian.


Quote:
Originally Posted by mike2010 View Post
Trying to figure out which Intrusion Detection System would be best for me. I've got a CentOs 5 / Linux / Apache system.
"The best" is as vague as it gets. But since you've mentioned "user friendly" too maybe it's just you're afraid to invest time to learn to handle an IDS? Given the fact you're running something on Apache I'd suggest you review the machines access controls and exposed services and complement your SW toolkit with some initial assessment tools like Tiger and OpenVAS (Atomic Rocket Turtle repo, run it from a remote host), a rootkit and malware scanner like Chkrootkit or Rootkit Hunter (OSSEC HIDS includes a scanner), a filesystem integrity checker like Samhain or Aide, Snort + Guardian, Logwatch (and read the reports), fail2ban or denyhosts and mod_security.

This is by no means complete. Do search the 'net for the term "hardening" (or see this) using those correctly you stand a better chance.
 
Old 01-11-2010, 08:29 PM   #4
mike2010
Member
 
Registered: Jan 2009
Posts: 132

Original Poster
Rep: Reputation: 15
arghh, esaym's seemed more simple.

I have most things / ports closed off.. but they tell me I should still install CLAM AV & and an IDS to feel more safe.

I even have SSH / FTP shutoff to only my IP as well. run Yum Updates daily as well.


Quote:
Originally Posted by unSpawn View Post
a rootkit and malware scanner like Chkrootkit or Rootkit Hunter (OSSEC HIDS includes a scanner), a filesystem integrity checker like Samhain or Aide, Snort + Guardian, Logwatch (and read the reports), fail2ban or denyhosts and mod_security.
I've got WatchDog installed.. and it has rootkit hunter with it. But my tech guys say rkhunter sucks.

So is PSAD kind of like syslog ? better than syslog ?

Maybe thats all I need. I need something simple / easy to configure..and gets the job done.

no thoughts on OSSEC ?
 
Old 01-12-2010, 01:31 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by mike2010 View Post
Maybe thats all I need. I need something simple / easy to configure..and gets the job done.
People choose what they like, not what they need. My point was that server hardening and auditing is important and it should not be handled by one tool. If you like your "tech guy's" quality assesments and like esaym's yellow brick road better then by all means follow it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[HELP]SNORT PROBLEMS(IDS)-service snort start JayCool Linux - Software 5 03-15-2009 12:34 PM
developing an ids using snort chax Linux - Security 1 01-10-2006 12:20 PM
developing an ids using snort chax Linux - Networking 1 01-10-2006 11:51 AM
Snort/ACID as an IDS WeNdeL Linux - Security 4 09-10-2004 12:14 PM
snort (ids) not working please help!!! crealkillerI75 Slackware 5 07-18-2002 03:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 01:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration