OSSIM Fedback



Hello everyone,

I have been following these lists for some time now and have seen some
messages on OSSIM (www.ossim.net) [Open Source Security Information
Management]. It seems like a great product but lacks documentation and
reviews on the Internet.

I am looking for some feedback on the usefulness and practicaility
(interms or maintenance and configuration) of this software. I am
mainly interested in OSSIM as a corelation tool / log analysis for
now. But if it works well as an IDS I would like to propose this as an
alternative to commercial IDS to the management.

Has anyone tried the latest version of the product (0.9.9)? Any
feedback on installation and usability would be great.

I would be very much interested in hearing your success or horror
stories with this.

I have searched the web for 3rd party reviews on this. Haven't found
much. So if you know of any please let me know.

Thanks.

KoolK3

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: [fw-wiz] RE: In defense of non standard ports
    ... > professionals with some pull with management. ... This is the frustration of many technical security professionals. ... Deploying IDS doesn't help this issue long-term. ... Not show them how valuable their firewall investment is? ...
    (Firewall-Wizards)
  • RE: OSSIM Fedback
    ... I tried to use OSSIM in the past without much success. ... alternative to commercial IDS to the management. ... feedback on installation and usability would be ...
    (Pen-Test)
  • Re: IDS Stealth Mode
    ... the IDS would have to be compromised in order to give the attacker access to the same L2 ... Have your management interface terminate on a "DMZ" or other type of restricted network, ...
    (Focus-IDS)
  • Re: Triggering IDS
    ... something similar to let you see what happens when your IDS triggers? ... vulnerability management needs. ... Download FREE whitepaper on how a managed service can help you: ...
    (Pen-Test)
  • IDS Management/SIM Systems
    ... Information Management System that integrates monitoring capabilities of ... What IDS are you using and why concern for SNMP ... However an organisation which is running a NMS might wish to incorporate IDS, ...
    (Focus-IDS)