also @ TechSpot: Motorola Droid 4 unboxing, hands-on video
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Software > Software Apps

Download Now:

Intrusion Detection System

Thread Tools Search this Thread
  #1  
Old 02-19-2007
Newcomer, in training
 
Member since: Aug 2006, 10 posts
Intrusion Detection System

I am looking for an IDS that tracks an intruders activities in the event of a breach. Thanks.
  #2  
Old 02-19-2007
Nodsu's Avatar
TechSpot Evangelist
 
Location: Estonia
Member since: Feb 2002, 9,431 posts
System specs
You mean something that recognises a breach and then, instead of blocking the attempt, carefully starts to monitor and log the attacker's activities?

There can be no automated solution for that. You'd need all the breaches and the attackers to act in a predictable (machine-trackable) way and that's just impossible. Besides, an IDS can only monitor stuff that goes through it. So if I can break into a system on your LAN and get an SSH tunnel going, then I can do everything on your LAN through that SSH tunnel without the IDS being able to see anything but encypted packets.

Maybe you are interested in so-called honepots or honeynets instead?
  #3  
Old 02-19-2007
Newcomer, in training
 
Member since: Aug 2006, 10 posts
I've looked at that option as well. Maybe I should have worded my request that I was interested in some type of utility to work in conjunction with an IDS.
I've also found a program known as Tripwire, that while it doesn't protect your network, it tracks changes made to files on an ongoing basis in the event of a breach.
  #4  
Old 02-19-2007
jobeard's Avatar
TechSpot Ambassador
 
Location: Southern Calif.
Member since: Apr 2005, 10,832 posts
Tripwire and IDS Issues

Quote:
Originally Posted by RJ3301
I've also found a program known as Tripwire, that while it doesn't protect your network, it tracks changes made to files on an ongoing basis in the event of a breach.
Tripwire -->YES :giddy: does exactly what an IDS is intended for!

For Windows systems, install Gygwin as a Unix compatible interface.
Under that, Install Tripwire.

Now for the lecture ( sorry )

All IDS systems are reactive just like all AV systems; they're useful after
your system is infected. The nice facility of the IDS is it provides postmortem
analysis as to WHAT WAS CHANGED
(since the last base line was taken) and therein lies the problem --
keeping it up todate with every install.

You save space and time by configuring an IDS to scan ONLY those areas which
impact the integrity of the System; meaning you avoid scanning USER directories.
IMO, users are recovered via a backup solutions.
Closed Thread

Similar Topics
Topic Replies Forum
Possible security intrusion - Windows 7 RC 13 Virus and Malware Removal
Virus intrusion 8 Virus and Malware Removal
"Spyware Detection Alert" in system tray as little red ! ball 1 Virus and Malware Removal
cpu intrusion error 1 Introduce yourself

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 01:29 AM.