OSSEC Host-Based IDS v0.2 available

From: Daniel Cid (danielcid_at_yahoo.com.br)
Date: 08/12/05

  • Next message: Bill Stout: "RE: Looking for HIDS-only products for XP/2000Pro"
    Date: Fri, 12 Aug 2005 18:27:00 -0300 (ART)
    To: focus-ids@securityfocus.com
    
    

    OSSEC HIDS is a self-contained system for Host-based
    intrusion detection. It performs log extraction,
    integrity checking and health monitoring. All this
    information is correlated and analyzed by a single
    engine, creating a very powerfull and scalable
    detection tool.

    As an HIDS, agents need to be installed on every
    server/system to be monitored. On each of these
    systems, the OSSEC HIDS agent will collect every log
    generated (in real time), perform integrity checking
    and health monitoring.

    These information will be encoded, encrypted and sent
    to the OSSEC HIDS analysis server.

    On the OSSEC HIDS analysis server, these events will
    be compared against a set of "analysis rules", checked
    using the "FTS" detection and using a statistical
    analysis. The analysis server can also receive syslog
    messages remotely (UDP 514) and analyze Snort,
    Barnyard and Apache logs (for better correlation).

    These new version includes a lot of fixes, new
    features and much more detection rules.

    To look at our log analysis rules:
    http://www.ossec.net/hids/rules/

    To download:
    http://www.ossec.net/hids/files/ossec-hids-0.2.tar.gz

    For more information:
    http://www.ossec.net/hids/

    Thanks,

    --
    Daniel B. Cid, CISSP
    daniel.cid@gmail.com
    __________________________________________________
    Converse com seus amigos em tempo real com o Yahoo! Messenger 
    http://br.download.yahoo.com/messenger/ 
    ------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it 
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    ------------------------------------------------------------------------
    

  • Next message: Bill Stout: "RE: Looking for HIDS-only products for XP/2000Pro"

    Relevant Pages

    • OSSEC HIDS v0.2 available
      ... OSSEC HIDS is a self-contained system for Host-based ... intrusion detection. ... integrity checking and health monitoring. ... On the OSSEC HIDS analysis server, ...
      (Security-Basics)
    • OSSEC Host-Based IDS v0.1
      ... OSSEC HIDS is a self-contained system for Host-based ... intrusion detection. ... perform integrity checking and health monitoring. ... On the OSSEC HIDS analysis server, ...
      (Focus-IDS)