Misplaced Pages

Host-based intrusion detection system comparison

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.

This is an old revision of this page, as edited by 98.6.18.132 (talk) at 14:27, 19 October 2017 (OSSEC supports Debian based systems). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Revision as of 14:27, 19 October 2017 by 98.6.18.132 (talk) (OSSEC supports Debian based systems)(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

Comparison of Host-based intrusion detection system components and systems.

Free software

As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.

Package Year Ubuntu CentOS File Network Logs Config Sane defaults Notes
OSSEC 2017 Yes No Yes Yes Yes Yes
Samhain 2016 Yes No Yes No Partial No
Snort 2015 Yes Yes No Yes No
chkrootkit 2017 Yes No Yes No Partial
rkhunter 2014 Yes Yes Yes No No Yes Yes
unhide 2012 Yes Yes No No No proc ps compare
Sguil 2017 No No No Yes No
Logwatch 2017 Yes Yes No No Yes No
Logcheck 2017 Yes Yes No No Yes No
Epylog 2014 Yes Yes No No Yes
SWATCH 2015 Yes Yes No No Yes
sagan 2017 Yes No No No Yes
aide 2016 Yes Yes Yes No No No
tripwire 2013 Yes Yes Yes No No

Proprietary software

Package Year Linux Windows File Network Logs Config Notes
Lacework 2017 Yes Yes Yes Yes Yes Yes
Verisys 2016 Yes Yes
Nessus 2017 Yes Yes Yes

References

  1. Last updated
  2. Repositories
  3. Repositories
  4. "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
  5. Last
  6. "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
  7. "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
  8. "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
  9. lastlog, wtmp, utmp, wtmpx
  10. "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
  11. "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
  12. "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
  13. "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
  14. "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
  15. "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
  16. "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
  17. "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
  18. "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
  19. "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
  20. "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
  21. "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
  22. "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
  23. "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
  24. "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
  25. "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
  26. "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
  27. "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
  28. "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
  29. "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
  30. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  31. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
  32. Last updated

External links

Category: