hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : The best Intrusion Detection System
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

The best Intrusion Detection System

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 03-16-2003, 06:03 PM
M0NkEY M0NkEY is offline
Web Hosting Guru
 
Join Date: Dec 2002
Posts: 316
Question

The best Intrusion Detection System


Anyone know of a really good Intrusion Detection System???


Preferably Free

Reply With Quote


Sponsored Links
  #2  
Old 03-16-2003, 06:10 PM
phactor phactor is offline
Web Hosting Evangelist
 
Join Date: Nov 2002
Posts: 536
snort + acid?

__________________
yeah.. i'm useless!

Reply With Quote
  #3  
Old 03-16-2003, 06:15 PM
M0NkEY M0NkEY is offline
Web Hosting Guru
 
Join Date: Dec 2002
Posts: 316

__________________


Reply With Quote
Sponsored Links
  #4  
Old 03-16-2003, 06:17 PM
phactor phactor is offline
Web Hosting Evangelist
 
Join Date: Nov 2002
Posts: 536
yes

i use it and is very good

good luck

__________________
yeah.. i'm useless!

Reply With Quote
  #5  
Old 03-16-2003, 06:34 PM
Patrick Patrick is offline
Stairway To Hosting
 
Join Date: Mar 2003
Location: Canada
Posts: 7,929
Hands down -- Snort.

Reply With Quote
  #6  
Old 03-16-2003, 08:33 PM
Luxore Luxore is offline
Web Hosting Guru
 
Join Date: Nov 2002
Location: Bay Area, California
Posts: 309
have they fixed that security problem in it yet?

Reply With Quote
  #7  
Old 03-16-2003, 09:00 PM
M0NkEY M0NkEY is offline
Web Hosting Guru
 
Join Date: Dec 2002
Posts: 316
Quote:
Originally posted by Luxore
have they fixed that security problem in it yet?
*Raised Eyebrow*

Reply With Quote
  #8  
Old 03-16-2003, 09:04 PM
cubision cubision is offline
Web Hosting Evangelist
 
Join Date: Nov 2002
Posts: 510
Which security problem are you refering to? Every piece of software has security bugs ... maybe you are refering to one of the most recent, the buffer overflow one?

Reply With Quote
  #9  
Old 03-16-2003, 09:20 PM
Luxore Luxore is offline
Web Hosting Guru
 
Join Date: Nov 2002
Location: Bay Area, California
Posts: 309
yup yup

at cert, second one down on "new and notable"


Reply With Quote
  #10  
Old 03-16-2003, 09:54 PM
inteltechs inteltechs is offline
Web Hosting Master
 
Join Date: Feb 2003
Posts: 2,289
I don't like snort at all... it will take all your cpu usage...

__________________
P4HOST.COM -- Specialize in quality Web Hosting solutions.
Affordable -- Prices are very comparative
Reliable -- Very low load average guaranteed. 60 day money back. Fast Support --Support Forum -- Providing hosting since 2003

Reply With Quote
  #11  
Old 03-16-2003, 11:12 PM
cubision cubision is offline
Web Hosting Evangelist
 
Join Date: Nov 2002
Posts: 510
I haven't seen any abnormal CPU usage on machines with snort ... mind describing your experience? What version/what cpu loads were you experiencing?

Reply With Quote
  #12  
Old 03-16-2003, 11:47 PM
RogelioH RogelioH is offline
Junior Guru
 
Join Date: Nov 2002
Posts: 216
Hi Intel,

Snort is a nice piece of cake, but are you sure you are running it right with correct config? Ive heard that if you run it wrong or configure it wrong it can hurt cpu.

__________________
Rogelio Hackett
Remedy Hosting Services
RogelioH@RemedyHosting.Com
RemedyHosting.Com - Providing A Remedy To All Hosting.

Reply With Quote
  #13  
Old 03-16-2003, 11:54 PM
M0NkEY M0NkEY is offline
Web Hosting Guru
 
Join Date: Dec 2002
Posts: 316
Hmmm... any suggestions for an IDS I can install easily on boxes with users already on them. One that will have a low risk of "funking" stuff up?

I've never installed snort and I don't want to practice on a box with customers on it.

Reply With Quote
  #14  
Old 03-17-2003, 01:05 AM
timelord timelord is offline
WHT Addict
 
Join Date: Nov 2002
Posts: 115
There are two types of IDS systems - HIDS (host intrusion detection system) and NIDS (network intrusion detection system). An example of a HIDS would be tripwire, and example of NIDS would be snort or any of the standalone commerical products.

In independent testing (in 2002), snort beat the commericail products from Enteresys and Cisco. I can tell you that I had it running on a 400Mhz machine monitoring a full (always busy) T1 and it was taking about 30-40% of the CPU. However, I was having it log to a MySQL database, and I didn't perform some of the steps needed to mitigate the performance impact (since it wasn't an issue.)

Having said all that, I would not recommend putting ANY NIDS on an active machine - it should be on a dedicated machine. Several reasons for this, including the fact that if somebody DOES breakin to your system, having the IDS on it means that they can hide the evidence that they were there (the same way they can clean stuff from the log files.) Another thing to remember is that you could be recording user name and passwords, and you certainly don't want that on the same machine as your users. Get an old machine, run a strip down Linux on it (www.devil-linux.org has one that is perfect for this), and only have it run Snort (and the associated components like MySQL [to log the attack records], Acid, etc.).

And yes - the buffer overflow issue has been resolved.

__________________
Dean Nedelman
TimeLord Consulting
http://www.timelord.com
"Systems programers are the high priests of a low cult"

Reply With Quote
  #15  
Old 03-17-2003, 01:13 AM
voided voided is offline
New Member
 
Join Date: Mar 2003
Posts: 2
check out puresecure from demarc

www.demarc.com

its just amazing... free for personal use, a bit pricey for commercial though. i love it

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Nginx Web Server Adds Device Detection at Server Layer with dotMobi DeviceAtlas Module Web Hosting News 2013-01-09 11:33:22
Alert Logic Adds Cloud Computing Security Tools for Amazon EC2 Customers Web Hosting News 2012-03-21 11:24:05
Inside Alert Logic and Datapipe's Fully Managed Network Security for AWS Web Hosting News 2011-10-26 15:09:29
Alert Logic, Datapipe Offer Fully Managed Network Security for AWS Customers Web Hosting News 2011-09-21 15:00:26
Web Host SingleHop Offers 1H.com Automation Software to Tandem Resellers Web Hosting News 2011-07-25 15:12:57


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?