Help With Intrusion Detection

Reply

Join Date: Aug 2008
Posts: 1
Reputation: oasisbhrnw is an unknown quantity at this point 
Solved Threads: 0
oasisbhrnw oasisbhrnw is offline Offline
Newbie Poster

Help With Intrusion Detection

 
0
  #1
Aug 25th, 2008
Hi all,

I need to setup a intrusion detection system for about 15 servers (Windows 2003 and MAC OS X Server). The problem is, I really don't know much about IDS. I would like to use free software. I have heard of SNORT, and from what I can tell, it monitors packets on your network. I was wondering, can it also monitor logs? Anyway, I was just wondering what everyone else out there uses. Any help is appreciated, thanks.
Reply With Quote Quick reply to this message  
Join Date: Aug 2008
Posts: 278
Reputation: mackone is on a distinguished road 
Solved Threads: 3
mackone mackone is offline Offline
Posting Whiz in Training

Re: Help With Intrusion Detection

 
0
  #2
Sep 4th, 2008
I read in reviews that SNORT has up-to-date intrusion detection (signature, etc.) rule files, a very large and happy user base, free user support forums, and commercial support service available. It allows installation with a MySQL database as an option, allowing alerts and related information to become accessible via ordinary SQL-related tools for user-defined analysis. It can also be installed with an analysis tool called ACID.

Open-source alternatives to SNORT exist. Here are just a few.
In the Windows NT/2000 camp LANGuard S.E.L.M. (Security Event Log Monitor), available in a single-server/five-workstation evaluation version.

ISS (Internet Security Systems) has several different products for NT/2000 and Solaris, including the RealSecure IDS, available for evaluation download.
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 372
Reputation: TheOgre is a jewel in the rough TheOgre is a jewel in the rough TheOgre is a jewel in the rough 
Solved Threads: 6
TheOgre's Avatar
TheOgre TheOgre is offline Offline
Posting Whiz

Re: Help With Intrusion Detection

 
0
  #3
Sep 9th, 2008
You can also use OSSEC-HIDS (free, OSS), which monitors logs and sends alerts in real-time, and it also monitors Snort logs.
If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- former White House cybersecurity czar Richard Clarke
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Network Security Forum
Thread Tools Search this Thread



Tag cloud for Network Security
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC