Host-based intrusion detection system comparison: Difference between revisions

Content deleted Content added
No edit summary
 
(41 intermediate revisions by 23 users not shown)
Line 1:
Comparison of [[host-based intrusion detection system]] components and systems.
 
==[[Free and Open Sourceopen-source software]]==
As per the [[Unix philosophy]] a good HIDS is composed of multiple packages each focusing on a specific aspect.
{| class="wikitable sortable"
|-
! Package
! Last Update
! Updated
! Ubuntu[[Debian]] <refsmall>Official Repositories</refsmall>
! CentOS[[AlmaLinux]] <refsmall>Official Repositories</refsmall>
! [[openSUSE]] <small>Official Repositories</small>
! File
! Network
! Logs
! [[Information_technology_security_audit|Config]]
! Sane defaults
! Notes
|-
| [[OSSEC]]
| 20172025
| {{yesno}}<ref>{{cite web |url=https://ossec.github.io/downloads.html#apt-automated-installation-on-ubuntu-and-debian |title=Downloads OSSEC|publisher=OSSEC|accessdate=2017-10-19 }} OSSEC for Debian Based systems</ref>
| {{yesno}}<ref>{{cite web |url=https://ossec.github.io/downloads.html#rhel-centos-fedora-and-others |title=Downloads OSSEC|publisher=OSSEC|accessdate=2017-10-29 }} OSSEC for RHEL/Fedora Based systems</ref>
| {{yes}}<ref>{{cite web |url=https://software.opensuse.org/package/ossec-hids |title=ossec-hids|publisher=openSUSE OBS|accessdate=2024-08-11 }} An Open Source Host-based Intrusion Detection System </ref>
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
|
|
|-
|Wazuh
|2025<ref>{{cite web |url=https://documentation.wazuh.com/current/release-notes/index.html |title=Wazuh documentation Release notes|accessdate=2025-07-16 }}</ref>
| {{no}}
| {{no}}
| ?
| {{noyes}}
| {{noyes}}
| {{yes}}
| {{yes}}
|-
| [[Samhain_(software)|Samhain]]
| 20162023
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=samhain |title=Samhain |publisher=Ubuntu |accessdate=2017-04-19 }} Samhain in the Ubuntu Repositories</ref>
| {{no}}
| {{yes}}<ref>{{cite web |url=https://software.opensuse.org/package/samhain?search_term=Samhain |title=Samhain |publisher=openSUSE OBS|accessdate=2024-08-11 }} File integrity and host-based IDS</ref>
| {{yes}}
| {{no}}
| {{partial}}<ref>Last</ref>
|
| {{no}}
|
|-
| [[Snort_(software)|Snort]]
| 2025<ref>{{cite web |url=https://github.com/snort3/snort3/releases |title=snort3/snort3 Releases|accessdate=2025-07-16 }}</ref>
| 2018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=snort |title=Snort |publisher=Ubuntu |accessdate=2017-04-19 }} Snort in the Ubuntu Repositories</ref>
| {{yesno}}<ref>{{cite web |url=https://pkgs.org/download/snort |title=Snort |publisher=Cisco Systems |accessdate=2017-05-31 }} Snort in the CentOS Repositories</ref>
| {{no}}
| {{no}}
| {{yes}}
| {{no}}
|
|
|-
| [[chkrootkit]]
| 20172023
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=chkrootkit |title=ChkRootkit |publisher=Ubuntu |accessdate=2017-04-19 }} ChkRootkit in the Ubuntu Repositories</ref>
| {{no}}
| {{yes}}
| {{yes}}
| {{no}}
| {{partial}}<ref>lastlog, wtmp, utmp, wtmpx</ref>
|
|
|-
Line 64 ⟶ 75:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the CentOS Repositories</ref>
| {{yes}}
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
| {{yes}}
|Ubuntu 18.04 LTS has some problems.{{fact|date=December 2018}}
|-
| [http://www.unhide-forensics.info unhide]<ref>{{cite web |url=https://packages.debian.org/search?keywords=unhide |title=unhide |publisher=debian |accessdate=2017-04-17 }}unhide is notable because it's part of Debian and Fedora</ref>
Line 75 ⟶ 86:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the CentOS Repositories</ref>
| {{yes}}
| {{no}}
| {{no}}
| {{no}}
|
| proc ps compare
|-
| [[Sguil]]
| 2017
| {{no}}
| {{no}}
| {{no}}
Line 90 ⟶ 102:
| {{no}}
|
|
|-
Line 97 ⟶ 108:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the CentOS Repositories</ref>
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
|
| {{no}}
|
|-
Line 108 ⟶ 119:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the CentOS Repositories</ref>
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
|
| {{no}}
|
|-
Line 119 ⟶ 130:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the CentOS Repositories</ref>
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
|
|
|
Line 130 ⟶ 141:
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the CentOS Repositories</ref>
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
|
|
|
|-
| [[Sagan_(software)|sagan]]
| 20172021
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=sagan |title=Sagan |publisher=Ubuntu |accessdate=2017-04-19 }} Sagan in the Ubuntu Repositories</ref>
| {{no}}
| {{no}}
| {{no}}
Line 145 ⟶ 157:
| {{yes}}
|
|
|
|-
| [[Advanced_Intrusion_Detection_Environment|aide]]
| 20162025
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the CentOS Repositories</ref>
| {{yes}}
| {{yes}}
| {{no}}
| {{no}}
| yes
| uses libs for routines
| {{no}}
|
|-
| [[Open_Source_Tripwire|tripwire]]
| 20132018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref>
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the CentOS Repositories</ref>
| {{yes}}
| {{yes}}
| {{no}}
| {{no}}
|
|
|
|-
| [[Tiger_(security_software)|Tiger]]
| 2018
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tiger |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref>
| {{no}}
| {{no}}
| {{yes}}
| {{no}}
| {{no}}
| {{yes}}
| 3/42 modules are Debian specific.
|-
|}
Line 195 ⟶ 217:
|
|-
| [[Verisys]]
| 2018
| {{yes}}
Line 214 ⟶ 236:
| {{yes}}
|
|-
|[https://www.atomicorp.com/atomic-enterprise-ossec/ Atomicorp]
|2019
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
|Commercially enhanced version of OSSEC
| -
|[https://spartan.mobilefx.com/ Spartan]
|2021
| {{no}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
| {{yes}}
|Websocket API, IP to Country mapping, DynDNS Integration
|}