RE: IDS

From: Trevor Cushen (trevor.cushen@sysnet.ie)
Date: 03/12/02


From: "Trevor Cushen" <trevor.cushen@sysnet.ie>
To: "'Gerard Fremaint'" <frank@prtc.net>
Date: Tue, 12 Mar 2002 10:52:44 -0000

Intrusion Detection System

It is used to monitor traffic or activity on a network or host for signs
of intrusion etc. You will not get very far in your investigation
without hearing about Snort for both Unix and NT, simply because it is
excellent. Demarc will also grace your screen in many a google search
before too long.
Quick pointers for further investigation,

Network based tools used for IDS:
Snort
Demarc
------- also note
Tcpdump
Etherpeek
Ethereal
IPWatcher

Host based IDS tools:
Tripwire
regmon
MD5 tools

stuck to think of more at the moment sorry.
Good luck.

Trevor

-----Original Message-----
From: Gerard Fremaint [mailto:frank@prtc.net]
Sent: 10 March 2002 03:26
To: security-basics@securityfocus.com
Subject: IDS

what is an IDS ?

******************************************************************************

This email and any files transmitted with it are confidential and intended
solely for the use of the individual or entity to whom they are addressed.

If you have received this message in error please notify SYSNET Ltd., at
telephone no: +353-1-2983000 or postmaster@sysnet.ie

******************************************************************************



Relevant Pages

  • Re: IDS is dead, etc
    ... > wouldn't call 'em an IDS, I think they're something different, much ... the host. ... Ensure Reliable Performance of Mission Critical Applications ... Precisely Define and Implement Network Security and Performance Policies ...
    (Focus-IDS)
  • [fw-wiz] Corporate H/N IPS
    ... Two new categories will be Host and Network Intrusion Prevention Systems, ... IDS, they actively block traffic deemed as malicious, almost like a firewall ... previous names for a HIPS have included Network Node IDS ...
    (Firewall-Wizards)
  • Networking IDS Correlation Question
    ... correlates Intrusion Detection System (IDS) data from network and host based ... both internal and external to the network. ...
    (Focus-IDS)
  • Re: how to find hidden host within LAN
    ... I would also recommend placing an IDS (intrusion detection ... in a manner where they are "hidden" on the network by not using an IP ... In the last week i notice in the iptables logs that a host within ... my lan is doing a lot of traffic. ...
    (RedHat)
  • RE: Host Based IDS Recommendations?
    ... Subject: Host Based IDS Recommendations? ... Precisely Define and Implement Network Security & Performance ...
    (Focus-IDS)