free Unix intrusion detection systems?
Feb. 19th, 2008 02:15 pmWhat intrusion detection toolkits does the modern Unix admin typically turn to? Here are some of the ones I'm aware of:
Those of you who have explored this issue in more depth than I have: what tools do you use and why? Have you actually experienced an attack while guarded by any of these tools, and how did they perform?
- Snort
- Tiger (appears to be under active development now?)
- LIDS (seems to require kernel patching)
- PortSentry/SentryTools
- chkrootkit
Those of you who have explored this issue in more depth than I have: what tools do you use and why? Have you actually experienced an attack while guarded by any of these tools, and how did they perform?