Intrusion Detection Tools

Modified 5 October 2009

System Intrusion Detection

Assuming you got your system into a reasonable state, you would like to keep it there. Or, at least you would like to know if it is changed!

Network Intrusion Detection

Note carefully that most "network intrustion detection" system really detect an attack and not an intrusion. Still possibly useful, just make sure you understand what a tool really does.

Also be somewhat skeptical of the real need for NID. If you are running BSD, do you really care that someone on the other side of the planet is trying to exploit a risk only found on Microsoft SQL Server? Is it appropriate to waste your time being "warned" about this complete non-risk? Aggressive NID can be a denial-of-service attack against yourself!

Snort is a great tool that detects and diagnoses scans, probes, and attempted attacks. http://www.snort.org/

Tools to automatically analyze audit trails for suspicious events.

A list of other log analysis tools: http://counterguide.com/listing.php?type=logs

Also see Purdue's CERIAS group, http://www.cerias.purdue.edu/, for current research in this challenging area.


Back to the main Security Page

Click here to inquire about advertising on this or any page on this site.
Home Unix/Linux Networking Infosec Travel Technical Radio Site Map Contact
Use /bin/vi! Manipulate images with ImageMagick! Hosted on OpenBSD
Hosted on Apache This site is viewable with any browser Valid XHTML 1.1! Valid CSS!
© Bob Cromwell Sep 2010. Created with /bin/vi and ImageMagick, hosted on OpenBSD with Apache.    Root password available here, privacy policy here.