Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Best Host IDS Tools

From: Jerry <gll(at)inel.gov>
Date: Tue Dec 24 2002 - 12:16:57 EST

frank wrote:

> I have just setup my Web server on solaris platform and is planning to

You have 4 different intent tools listed..

AIDE is indeed a host ids...I have tested it, but not had the chance to really deploy it. AIDE looks at all aspects of the system,: file space (user induced DOS), password files, etc.

Snort is a NETWORK IDS, not really a host IDS. Snort only alerts/captures based on network traffic.

Tripwire is used to make sure critical files have not changed via checksum processes. This tool knows nothing of
network intrusions, etc.

Chkrootkit is a tool used to scan a system fro KNOWN traces of root kits.

Do you need help?X

In truth, you need to deploy ALL of them for a nearly true secure environment.

--
------------------------------------------------------------------
Jerry Litteer
Cyber Security Office             e-mail:  gll@inel.gov
Idaho National Engineering and Environmental Lab. (INEEL)
POB 1625 M.S. 3640                Phone: (208) 526-9117
Idaho Falls, Id. 83415-3640       FAX:   (208) 526-9366
Received on Fri Dec 27 12:11:19 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:05 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library