Re: Host Based IDS Recommendations?

From: Mark Teicher (mht3_at_earthlink.net)
Date: 10/19/03

  • Next message: Pat Stangler: "Re: Experiences with Toplayer Attack Mitigator IPS"
    Date: Sun, 19 Oct 2003 14:10:27 -0600
    To: "edward gonzales" <egon007@msn.com>, focus-ids@securityfocus.com
    
    

    Host Based IDS Recommendations can be sorts into many different categories
    due to Okena and Sygate redefining their market space.

    But here goes

    Software Based HIDS

    Sygate Technologies Sygate Security Agent
    Innerwall Enclave
    Symantec Intruder Alert/Symantec Client Security
    ISS Site Protector/ISS Desktop Protector
    NAI Entercept
    Cisco Security Agent

    Some vendors classify themselves as both IDS and IPS solutions, but very
    few of them have IPS signatures that actually provide IPS like functionality

    /mark

    At 09:11 AM 10/16/2003, edward gonzales wrote:

    >Symantec has Intruder Alert 3.6 (formerly made by Axent) with agents for
    >Solaris, AIX, HP-UX, RH 7.x and Windows.
    >They also have their new Symantec Host IDS 4.x products, but not all of
    >the unix varients are out yet.
    >
    >
    >
    >> > I would like to find out for Windows boxes if there are any
    >> > recommendations for Host based IDS, i know that for unix there is AIDE,
    >> > linux, tripwire. What are the solutions for Windows machines? Would
    >> > running a software IDS that is capable of monitoring and protecting the
    >> > file systems a la tripwire with signed hashes kept in removable media be
    >> > sufficient? If there are, what are the usual suspects for host based IDS
    >> > that is used prevalently in industry? I'm hoping for both free and
    >> > commercial solutions
    >>
    >
    >_________________________________________________________________
    >Compare Cable, DSL or Satellite plans: As low as $29.95.
    >https://broadband.msn.com
    >
    >
    >---------------------------------------------------------------------------
    >FREE Whitepaper: Better Management for Network Security
    >
    >Looking for a better way to manage your IP security?
    >Learn how Solsoft can help you:
    >- Ensure robust IP security through policy-based management
    >- Make firewall, VPN, and NAT rules interoperable across heterogeneous
    >networks
    >- Quickly respond to network events from a central console
    >
    >Download our FREE whitepaper at:
    >http://www.securityfocus.com/sponsor/Solsoft_focus-ids_031015
    >---------------------------------------------------------------------------
    >

    ---------------------------------------------------------------------------
    FREE Whitepaper: Better Management for Network Security

    Looking for a better way to manage your IP security?
    Learn how Solsoft can help you:
    - Ensure robust IP security through policy-based management
    - Make firewall, VPN, and NAT rules interoperable across heterogeneous
    networks
    - Quickly respond to network events from a central console

    Download our FREE whitepaper at:
    http://www.securityfocus.com/sponsor/Solsoft_focus-ids_031015
    ---------------------------------------------------------------------------


  • Next message: Pat Stangler: "Re: Experiences with Toplayer Attack Mitigator IPS"

    Relevant Pages

    • Re: [Full-Disclosure] Is Marty Lying?
      ... > enough to buy the hype of signature-based IDS and to think products like ... The compromise must definately have been limited to ... > their network so if it gets compromised, ... > Snort/Sourcefire network's security. ...
      (Full-Disclosure)
    • Re: Is IDS/IPS worthless?
      ... IMHO IDS and IPS are not dead, quite the reverse, but in order to make them ... useful they require a degree of continued investment and support. ... is a case for network defense not requiring IDS/IPS to protect their network ... may lull the staff into a false sense of security. ...
      (Focus-IDS)
    • Re: Is IDS/IPS worthless?
      ... What experience I have with network auditing has forced home the idea ... no elephants -- it's easy to say that IDS is worthless when you aren't ... > operations and security is a critical component of IT. ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
      (Focus-IDS)
    • AW: Recent anti-NIDS Gartner article
      ... The Gartner article has a very narrow point of view. ... IMHO an IDS is more but a NIDS or IPS or whatever network-based IDS. ... Why do folks only talk about network based IDS? ... securiy-zones of different security and surveillance needs. ...
      (Focus-IDS)
    • Re: Is IDS/IPS worthless?
      ... > firewall instead of in front of it should BOTH ... > fill in the gap left by the false sense of security firewalls give (a ... > network services, and it is on the traffic related to these services ... IDS technology and I certainly believe in the usefullness of IDS. ...
      (Focus-IDS)