free Unix intrusion detection systems?
Feb. 19th, 2008 02:15 pmWhat intrusion detection toolkits does the modern Unix admin typically turn to? Here are some of the ones I'm aware of:
Those of you who have explored this issue in more depth than I have: what tools do you use and why? Have you actually experienced an attack while guarded by any of these tools, and how did they perform?
- Snort
- Tiger (appears to be under active development now?)
- LIDS (seems to require kernel patching)
- PortSentry/SentryTools
- chkrootkit
Those of you who have explored this issue in more depth than I have: what tools do you use and why? Have you actually experienced an attack while guarded by any of these tools, and how did they perform?
no subject
Date: 2008-02-19 07:41 pm (UTC)Haven't used it since last millennium, though.
no subject
Date: 2008-02-19 08:39 pm (UTC)no subject
Date: 2008-02-19 08:43 pm (UTC)no subject
Date: 2008-02-19 08:44 pm (UTC)no subject
Date: 2008-02-19 08:24 pm (UTC)no subject
Date: 2008-02-19 08:41 pm (UTC)