RE: which IDS

From: Chris Petersen (chris@idsroi.com)
Date: 11/14/02


Date: Thu, 14 Nov 2002 14:35:39 -0500
From: Chris Petersen <chris@idsroi.com>
To: 'Jill Tovey' <jill.tovey@bigbluedoor.com>, focus-ids@securityfocus.com

You can eval the entire Dragon suite for 30 days. NIDS and Server work
on Linux/unix. HIDS also supports Windows. Go to
http://dragon.enterasys.com/ where you can sign-up for a demo account.

Have fun,
Chris

> -----Original Message-----
> From: Jill Tovey [mailto:jill.tovey@bigbluedoor.com]
> Sent: Tuesday, November 12, 2002 3:02 AM
> To: focus-ids@securityfocus.com
> Subject: which IDS
>
>
>
>
> hi i am looking to test three different NID systems,
>
>
>
> I have at home, one win2k copmuter, one SuSE linux computer, both
>
> connected with a DG814 router,
>
>
>
> i will probably get snort but i need two more free ones, that
> i can test
>
> on these computers, i am a bit worried that i will maybe need
> an extra
>
> computer to put in the DMZ to run some, i ideally would just
> like two that
>
> i can run from my normal setup here
>
>
>
> it would be great if anyone can reccommend any ?
>
>
>
> Thanks,
>
>
>
> Jill
>



Relevant Pages

  • Re: [Full-Disclosure] IDS for Windows
    ... It should be Free or Shareware and perhaps it could work in a ... >HIDS or NIDS? ... I know Snort for Windows, ...
    (Full-Disclosure)
  • Re: host-based ids evaluation
    ... That is why NIDS is proactive, it will log the network traffic patterns ... As for NIDS and HIDS they work differently, ... >>>different types of IDS. ...
    (Focus-IDS)
  • RE: host-based ids evaluation
    ... If you are looking at a single system then you are a HIDS, ... You can now get into deeper distinctions regarding types of IDS techniques ... but HIDS vs. NIDS is as simple as the focus for the product. ... HIDS can detect local-to-local attacks (or ...
    (Focus-IDS)
  • Re: host-based ids evaluation
    ... noting that there is rarely any correlation between events generated by NIDS ... HIDS can also be very noisy, ... NIDS.....An exception could be an Inline IDS which stops the attacks getting ... > and NIDS will monitor the network activity under that (or above if I ...
    (Focus-IDS)
  • Re: host-based ids evaluation
    ... Personally, I think in most case HIDS is more of "reactive", and NIDS is ... While NIDS will/can gather all the information on the network. ... > a Host IDS looks within the host for evidence of intrusion. ...
    (Focus-IDS)

Quantcast