Misplaced Pages

Host-based intrusion detection system comparison: Difference between revisions

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
Browse history interactively← Previous editContent deleted Content addedVisualWikitext
Revision as of 14:27, 19 October 2017 edit98.6.18.132 (talk) OSSEC supports Debian based systems← Previous edit Latest revision as of 23:23, 11 August 2024 edit undo66.41.189.188 (talk) Free and open-source software 
(48 intermediate revisions by 30 users not shown)
Line 1: Line 1:
Comparison of ] components and systems. Comparison of ] components and systems.


==]== ==]==
As per the ] a good HIDS is composed of multiple packages each focusing on a specific aspect. As per the ] a good HIDS is composed of multiple packages each focusing on a specific aspect.
{| class="wikitable sortable" {| class="wikitable sortable"
|- |-
! Package ! Package
! Updated
! Year<ref>Last updated</ref>
! Ubuntu<ref>Repositories</ref> ! Ubuntu <small>Official Repositories</small>
! CentOS<ref>Repositories</ref> ! CentOS <small>Official Repositories</small>
! ] <small>Official Repositories</small>
! File ! File
! Network ! Network
! Logs ! Logs
! ] ! ]
! Sane defaults
! Notes ! Notes
|- |-
| ] | ]
| 2017 | 2022
| {{no}}<ref>{{cite web |url=https://ossec.github.io/downloads.html#apt-automated-installation-on-ubuntu-and-debian |title=Downloads OSSEC|publisher=OSSEC|accessdate=2017-10-19 }} OSSEC for Debian Based systems</ref>
| {{no}}<ref>{{cite web |url=https://ossec.github.io/downloads.html#rhel-centos-fedora-and-others |title=Downloads OSSEC|publisher=OSSEC|accessdate=2017-10-29 }} OSSEC for RHEL/Fedora Based systems</ref>
| {{yes}}<ref>{{cite web |url=https://software.opensuse.org/package/ossec-hids |title=ossec-hids|publisher=openSUSE OBS|accessdate=2024-08-11 }} An Open Source Host-based Intrusion Detection System </ref>
| {{yes}} | {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
|
|-
|Wazuh
|2022
| {{no}} | {{no}}
| {{no}}
| ?
| {{yes}} | {{yes}}
| {{yes}} | {{yes}}
| {{yes}} | {{yes}}
| {{yes}} | {{yes}}
| |
|
|- |-
| ] | ]
| 2016 | 2021
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=samhain |title=Samhain |publisher=Ubuntu |accessdate=2017-04-19 }} Samhain in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=samhain |title=Samhain |publisher=Ubuntu |accessdate=2017-04-19 }} Samhain in the Ubuntu Repositories</ref>
| {{no}} | {{no}}
| {{yes}}<ref>{{cite web |url=https://software.opensuse.org/package/samhain?search_term=Samhain |title=Samhain |publisher=openSUSE OBS|accessdate=2024-08-11 }} File integrity and host-based IDS</ref>
| {{yes}} | {{yes}}
| {{no}} | {{no}}
| {{partial}}<ref>Last</ref> | {{partial}}<ref>Last</ref>
| |
| {{no}}
| |
|- |-
| ] | ]
| 2015 | 2018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=snort |title=Snort |publisher=Ubuntu |accessdate=2017-04-19 }} Snort in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=snort |title=Snort |publisher=Ubuntu |accessdate=2017-04-19 }} Snort in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/snort |title=Snort |publisher=Cisco Systems |accessdate=2017-05-31 }} Snort in the CentOS Repositories</ref> | {{no}}<ref>{{cite web |url=https://pkgs.org/download/snort |title=Snort |publisher=Cisco Systems |accessdate=2017-05-31 }} Snort in the CentOS Repositories</ref>
| {{no}}
| {{no}} | {{no}}
| {{yes}} | {{yes}}
| {{no}} | {{no}}
| |
|
| |
|- |-
| ] | ]
| 2017 | 2023
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=chkrootkit |title=ChkRootkit |publisher=Ubuntu |accessdate=2017-04-19 }} ChkRootkit in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=chkrootkit |title=ChkRootkit |publisher=Ubuntu |accessdate=2017-04-19 }} ChkRootkit in the Ubuntu Repositories</ref>
| {{no}} | {{no}}
| {{yes}}
| {{yes}} | {{yes}}
| {{no}} | {{no}}
| {{partial}}<ref>lastlog, wtmp, utmp, wtmpx</ref> | {{partial}}<ref>lastlog, wtmp, utmp, wtmpx</ref>
| |
|
| |
|- |-
| ] | ]
| 2014 | 2018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the CentOS Repositories</ref>
| {{yes}}
| {{yes}} | {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| {{yes}}
| {{yes}} | {{yes}}
| |
Line 75: Line 86:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the CentOS Repositories</ref>
| {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| |
|
| proc ps compare | proc ps compare
|- |-
| ] | ]
| 2017 | 2017
| {{no}}
| {{no}} | {{no}}
| {{no}} | {{no}}
Line 90: Line 102:
| {{no}} | {{no}}
| |
|
| |
|- |-
Line 97: Line 108:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the CentOS Repositories</ref>
| {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| {{yes}} | {{yes}}
| |
| {{no}}
| |
|- |-
Line 108: Line 119:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the CentOS Repositories</ref>
| {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| {{yes}} | {{yes}}
| |
| {{no}}
| |
|- |-
Line 119: Line 130:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the CentOS Repositories</ref>
| {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| {{yes}} | {{yes}}
|
| |
| |
Line 130: Line 141:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the CentOS Repositories</ref>
| {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| {{yes}} | {{yes}}
| |
|
| |
|- |-
| ] | ]
| 2017 | 2021
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=sagan |title=Sagan |publisher=Ubuntu |accessdate=2017-04-19 }} Sagan in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=sagan |title=Sagan |publisher=Ubuntu |accessdate=2017-04-19 }} Sagan in the Ubuntu Repositories</ref>
| {{no}}
| {{no}} | {{no}}
| {{no}} | {{no}}
Line 145: Line 157:
| {{yes}} | {{yes}}
| |
|
| |
|- |-
| ] | ]
| 2016 | 2023
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the CentOS Repositories</ref>
| {{yes}}
| {{yes}} | {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| |
| {{no}}
| |
|- |-
| ] | ]
| 2013 | 2018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref> | {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the CentOS Repositories</ref> | {{yes}}<ref>{{cite web |url=https://pkgs.org/download/tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the CentOS Repositories</ref>
| {{yes}}
| {{yes}} | {{yes}}
| {{no}} | {{no}}
| {{no}} | {{no}}
| |
|
| |
|-
| ]
| 2018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tiger |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref>
| {{no}}
| {{no}}
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
| 3/42 modules are Debian specific.
|- |-
|} |}
Line 185: Line 207:
! Notes ! Notes
|- |-
| |
| 2017 | 2018
| {{yes}}
| {{yes}} | {{yes}}
| {{no}}
| {{yes}} | {{yes}}
| {{yes}} | {{yes}}
Line 195: Line 217:
| |
|- |-
| ] | Verisys
| 2016 | 2018
| {{yes}}
| {{yes}}
| {{yes}} | {{yes}}
| {{yes}} | {{yes}}
| |
| | {{yes}}
|
|
| |
|- |-
Line 214: Line 236:
| {{yes}} | {{yes}}
| |
|-
|
|2019
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
|Commercially enhanced version of OSSEC
|-
|
|2021
| {{no}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
|Websocket API, IP to Country mapping, DynDNS Integration
|} |}


Line 224: Line 266:
* *
* *
*





Latest revision as of 23:23, 11 August 2024

Comparison of host-based intrusion detection system components and systems.

Free and open-source software

As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.

Package Updated Ubuntu Official Repositories CentOS Official Repositories openSUSE Official Repositories File Network Logs Config Notes
OSSEC 2022 No No Yes Yes Yes Yes Yes
Wazuh 2022 No No ? Yes Yes Yes Yes
Samhain 2021 Yes No Yes Yes No Partial
Snort 2018 Yes No No No Yes No
chkrootkit 2023 Yes No Yes Yes No Partial
rkhunter 2018 Yes Yes Yes Yes No No Yes
unhide 2012 Yes Yes Yes No No No proc ps compare
Sguil 2017 No No No No Yes No
Logwatch 2017 Yes Yes Yes No No Yes
Logcheck 2017 Yes Yes Yes No No Yes
Epylog 2014 Yes Yes Yes No No Yes
SWATCH 2015 Yes Yes Yes No No Yes
sagan 2021 Yes No No No No Yes
aide 2023 Yes Yes Yes Yes No No
tripwire 2018 Yes Yes Yes Yes No No
Tiger 2018 Yes No No Yes No No Yes 3/42 modules are Debian specific.

Proprietary software

Package Year Linux Windows File Network Logs Config Notes
Lacework 2018 Yes No Yes Yes Yes Yes
Verisys 2018 Yes Yes Yes Yes Yes
Nessus 2017 Yes Yes Yes
Atomicorp 2019 Yes Yes Yes Yes Yes Yes Commercially enhanced version of OSSEC
Spartan 2021 No Yes Yes Yes Yes Yes Websocket API, IP to Country mapping, DynDNS Integration

References

  1. "Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems
  2. "Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
  3. "ossec-hids". openSUSE OBS. Retrieved 2024-08-11. An Open Source Host-based Intrusion Detection System
  4. "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
  5. "Samhain". openSUSE OBS. Retrieved 2024-08-11. File integrity and host-based IDS
  6. Last
  7. "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
  8. "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
  9. "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
  10. lastlog, wtmp, utmp, wtmpx
  11. "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
  12. "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
  13. "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
  14. "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
  15. "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
  16. "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
  17. "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
  18. "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
  19. "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
  20. "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
  21. "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
  22. "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
  23. "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
  24. "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
  25. "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
  26. "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
  27. "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
  28. "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
  29. "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
  30. "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
  31. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  32. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
  33. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  34. Last updated

External links

Category: