Want to protect your SOHO machine or LAN from rootkits and malware, but want something a little more real-time than simply running Chkrootkit or another rootkit detector after the fact? Consider OSSEC-HIDS, an open source host intrusion detection system. . According the OOSEC-HIDS Web site, it's more than a host intrusion detection system (IDS). It's also a security event manager and a security information manager, which makes it the security equivalent of a hat trick in hockey, a triple-play in baseball, or a rare triple-double in basketball. The link for this article located at Linux.com is no longer available. . According the OOSEC-HIDS Web site, it's more than a host intrusion detection system (IDS). It's also. protect, machine, rootkits, malware, something, little. . LinuxSecurity.com Team
OSSEC HIDS is an open source host-based intrusion detection system. It performs log analysis, integrity checking, rootkit detection, time-based alerting and active response. This is one of the most improved versions so far. It now includes support for squid, pure-ftpd, postfix and AIX ipsec logs (in addition to a lot of improvements to the previous rules). . The integrity checking engine now allows granular options, where you can specify exactly what options you want to monitor (checksum, size, ownership, etc). The rootkit detection had a lot of improvements too, reducing false positives on most of the systems and with a lot of new anomaly checks to detect kernel level rootkits. We also have a new website and the installation in 4 different languages (portuguese, english, german and turkish).
Get the latest Linux and open source security news straight to your inbox.