Looking for HIDS-only products for XP/2000Pro

From: Bill Stout (bill.stout_at_greenborder.com)
Date: 08/04/05

  • Next message: Sanjay Rawat: "Re: Deploying Host based IDS: is there any benefit ??"
    Date: Wed, 3 Aug 2005 21:19:51 -0700
    To: <focus-ids@securityfocus.com>
    
    

    I'm assuming most companies do both HIDS and blocking. Are there any
    companies which specialize in HIDS for XP/2000Pro? Specifically passive
    (worm/virus/Trojan) attacks, maybe with an online database for
    reference.

    In other words, if we have a product which protects against certain
    vectors (IE & Outlook), and we want to prove that it did protect them
    although it doesn't detect, what could I use to detect and identify
    specific attacks?

    Bill Stout
    Director of IT
    GreenBorder, Inc
    www.greenborder.com

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Sanjay Rawat: "Re: Deploying Host based IDS: is there any benefit ??"

    Relevant Pages

    • Re: host-based ids evaluation
      ... I agree with Toby's opinion on IDS terminology. ... these are sometimes referred to as "Network Node IDS". ... -> Logfile surveillance (classic HIDS) ... prevent most attacks from being performed if the target application does not ...
      (Focus-IDS)
    • Re: Looking for HIDS-only products for XP/2000Pro
      ... McAfeeEnterceptagents protects desktops and servers against ... zero-day and known attacks. ... On 8/4/05, Bill Stout wrote: ... > I'm assuming most companies do both HIDS and blocking. ...
      (Focus-IDS)
    • RE: host-based ids evaluation
      ... If you are looking at a single system then you are a HIDS, ... You can now get into deeper distinctions regarding types of IDS techniques ... but HIDS vs. NIDS is as simple as the focus for the product. ... HIDS can detect local-to-local attacks (or ...
      (Focus-IDS)
    • Re: host-based ids evaluation
      ... > I'd recommend against trying to use a vulnerability scanner to try ... A decent HIDS product will not necessarily light up ... > would have to write custom Nessus scripts if you want it to complete ... HIDS are best tested by performing actual attacks against ...
      (Focus-IDS)
    • R: host-based ids evaluation
      ... in industry not exist a clear definition of HIDS. ... its pros and cons against an NIDS. ... watching for remote-to-local attacks. ... HIDS behaviour is named NNIDS. ...
      (Focus-IDS)