Host-based intrusion detection system comparison

This is an old revision of this page, as edited by Tim@ (talk | contribs) at 16:44, 19 April 2017 (Free software). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Comparison of Host-based intrusion detection system components and systems.

As per the Unix philosophy a good HIDS is composed of multipule packages each focusing on a specific aspect.

Package Year[1] Ubuntu[2] CentOS[3] File Network Logs Config Notes
OSSEC 2017 No No Yes Yes Yes Yes
Lynis 2017 Yes[4] Yes No No No Yes
OpenVAS 2017 No No No No No Yes
Samhain 2016 Yes[5] No Yes No Partial[6]
Snort 2015 Yes[7] No No Yes No
chkrootkit 2017 Yes[8] No Yes No Partial[9]
rkhunter 2014 Yes[10] Yes Yes No No Yes
unhide[11] 2012 Yes[12] Yes No No No proc ps compare
Sguil 2017 No No No Yes No
Logwatch[13] 2016 Yes[14] Yes No No Yes
sagan 2017 Yes[15] No No No Yes
aide 2016 Yes[16] Yes Yes No No
tripwire 2013 Yes[17] Yes Yes No No
Package Year[18] Linux Windows File Network Logs Config Notes
Verisys 2016 Yes Yes
Nessus 2017 Yes Yes Yes

References

  1. ^ Last updated
  2. ^ Repositories
  3. ^ Repositories
  4. ^ "Lynis". Ubuntu. Retrieved 2017-04-19. Lynis in the Ubuntu Repositories
  5. ^ "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
  6. ^ Last
  7. ^ "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
  8. ^ "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
  9. ^ lastlog, wtmp, utmp, wtmpx
  10. ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
  11. ^ "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
  12. ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
  13. ^ "logwatch". debian. Retrieved 2017-04-17.logwatch is notable because it's part of Debian and Fedora
  14. ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
  15. ^ "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
  16. ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
  17. ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  18. ^ Last updated