re: windows 2000 Intrustion Detection

From: H C (keydet89@yahoo.com)
Date: 06/03/02


Date: Mon, 3 Jun 2002 05:55:46 -0700 (PDT)
From: H C <keydet89@yahoo.com>
To: jonathan@tranceport.net


> Could someone just outright come out and tell me
what
> the best package for intrusion detection is for a
> windows 2000 box.

As you've surely seen from responses so far, the
answer is a simple "no". "Best" is a relative term.
What do you consider "best"...reporting features?
Detection?

Have you considered intrusion protection using
mechanisms inherent to Win2K, like ACLs, etc? Have
you considered setting auditing and logging?

I've seen several posts recommending snort...but snort
runs on 2K, as well (check out the SiliconDefense
website for the binaries). There is no reason why you
can't use snort on 2K, even to the point of installing
it on the box itself w/ a ruleset specifically
designed for the box...remove all *nix/Linux-specific
rules, and any specific rules for applications you're
not using.

So, I'd recommend prevent first, then detection.
Detection can be based on the host, the network, or
both. How you choose to implement either is based on
your available resources...do you have the time and
effort to invest in learning something new, or is it a
matter of immediacy and you have the funds to pay for
a third-party application and a consultant to install
it?

__________________________________________________
Do You Yahoo!?
Yahoo! - Official partner of 2002 FIFA World Cup
http://fifaworldcup.yahoo.com



Relevant Pages

  • Re: True definition of Intrusion Prevention
    ... >Prevention versus Network Intrusion Detection, ... to be monitoring the integrity of the host's operation. ...
    (Focus-IDS)
  • Re: Intrusion Prevention
    ... > approach to IDS technologies and provides a number of advantages over ... > other detection systems, such as proactively detecting reconnaissance ... 100% no false positives, 'proactive' intrusion detection, intrusion ...
    (Focus-IDS)
  • Re: Specification-based Anomaly Detection
    ... >>intrusion detection, where most of the products are built on a misuse ... > used anomaly detection by building user profiles and was available from ... I meant NETWORK intrusion detection, ... 34/5 I-20133 Milano - ITALY ...
    (Focus-IDS)
  • Re: windows restriction is blocking my intrusion detection from turnin
    ... h4xor wrote: ... > able to be turned on and get the same message saying that it has ... ok i tried installing the update for the intrusion detection and once ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: SuSE Linux 9.2 and ACER Travelmate Centrino
    ... the wireless card and modem have been correctly ... But I cannot access the network, ... Installing 9.2 on it, made even ... distros provide good automated hardware detection and configuration and ...
    (comp.os.linux.hardware)