Read on full site | Join TechSpot! (it's free) | Bookmark / Share this



Intrusion Detection System

RJ3301
02-19-2007, 01:00 AM
I am looking for an IDS that tracks an intruders activities in the event of a breach. Thanks.

Nodsu
02-19-2007, 05:36 AM
You mean something that recognises a breach and then, instead of blocking the attempt, carefully starts to monitor and log the attacker's activities?

There can be no automated solution for that. You'd need all the breaches and the attackers to act in a predictable (machine-trackable) way and that's just impossible. Besides, an IDS can only monitor stuff that goes through it. So if I can break into a system on your LAN and get an SSH tunnel going, then I can do everything on your LAN through that SSH tunnel without the IDS being able to see anything but encypted packets.

Maybe you are interested in so-called honepots or honeynets instead?

Ad
02-19-2007, 05:36 AM
  

RJ3301
02-19-2007, 10:08 AM
I've looked at that option as well. Maybe I should have worded my request that I was interested in some type of utility to work in conjunction with an IDS.
I've also found a program known as Tripwire, that while it doesn't protect your network, it tracks changes made to files on an ongoing basis in the event of a breach.

jobeard
02-19-2007, 01:37 PM
I've also found a program known as Tripwire, that while it doesn't protect your network, it tracks changes made to files on an ongoing basis in the event of a breach.
Tripwire -->YES :giddy: does exactly what an IDS is intended for!

For Windows systems, install Gygwin as a Unix compatible interface.
Under that, Install Tripwire.

Now for the lecture ( sorry )

All IDS systems are reactive just like all AV systems; they're useful after
your system is infected. The nice facility of the IDS is it provides postmortem
analysis as to WHAT WAS CHANGED
(since the last base line was taken) and therein lies the problem --
keeping it up todate with every install.

You save space and time by configuring an IDS to scan ONLY those areas which
impact the integrity of the System; meaning you avoid scanning USER directories.
IMO, users are recovered via a backup solutions.

Post a reply, see related topics & more

Tip: Download Advanced SystemCare 3 Free - Clean, Repair, Protect & Optimize your PC.



 Top Technology News

TechSpot Blog: Disable Windows automatic check for solutions after a program crashes

Weekend Open Forum: Google Chrome OS and the future of cloud computing

Tech Tip of the Week: Unearth Region-Specific Windows 7 Themes

Gartner: PC shipments to grow 2.8% in 2009, revenue down 11%

Microsoft issues warning for IE6, IE7 security hole

LG X120 netbook to launch in the US for $180 with two-year AT&T contract

Intel's six-core Gulftown processor benchmarked months early

Another iPhone worm spotted, this time it's dangerous

More Tech News

  
 Software Downloads

FlashGot 1.2.0.9

RemoveIT Pro XT - SE 23.11.2009

Vuze (Formerly Azureus) 4.3.0.4

RemoveIT Pro v7 Enterprise 23.11.2009

Aloaha PDF Suite 3.9.172

Blindwrite Suite 6.3.1.5

RemoveIT Pro v7 Ultra 23.11.2009

More Downloads



Copyright © 1998-2009 TechSpot.com. TechSpot is a registered trademark. All Rights Reserved.