Jump to content

Host-based intrusion detection system comparison

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by 70.80.28.148 (talk) at 01:09, 4 May 2018 (Recent review of the software indicate problems on Ubuntu 18.04 LTS. Has of the May 3 2018.). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Comparison of host-based intrusion detection system components and systems.

As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.

Package Year[1] Ubuntu[2] CentOS[3] File Network Logs Config Sane defaults Notes
OSSEC 2017 Yes[4] Yes[5] Yes Yes Yes Yes
Samhain 2016 Yes[6] No Yes No Partial[7] No
Snort 2015 Yes[8] Yes[9] No Yes No
chkrootkit 2017 Yes[10] No Yes No Partial[11]
rkhunter 2017 Yes[12] Yes[13] Yes No No Yes Yes Ubuntu 18.04 LTS has some problems.
unhide[14] 2012 Yes[15] Yes[16] No No No proc ps compare
Sguil 2017 No No No Yes No
Logwatch[17] 2017 Yes[18] Yes[19] No No Yes No
Logcheck[20] 2017 Yes[21] Yes[22] No No Yes No
Epylog[23] 2014 Yes[24] Yes[25] No No Yes
SWATCH[26] 2015 Yes[27] Yes[28] No No Yes
sagan 2017 Yes[29] No No No Yes
aide 2016 Yes[30] Yes[31] Yes No No No
tripwire 2013 Yes[32] Yes[33] Yes No No
Package Year[34] Linux Windows File Network Logs Config Notes
Lacework 2017 Yes Yes Yes Yes Yes Yes
Verisys 2016 Yes Yes Yes Yes
Nessus 2017 Yes Yes Yes

References

  1. ^ Last updated
  2. ^ Repositories
  3. ^ Repositories
  4. ^ "Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems
  5. ^ "Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
  6. ^ "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
  7. ^ Last
  8. ^ "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
  9. ^ "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
  10. ^ "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
  11. ^ lastlog, wtmp, utmp, wtmpx
  12. ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
  13. ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
  14. ^ "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
  15. ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
  16. ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
  17. ^ "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
  18. ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
  19. ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
  20. ^ "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
  21. ^ "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
  22. ^ "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
  23. ^ "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
  24. ^ "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
  25. ^ "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
  26. ^ "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
  27. ^ "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
  28. ^ "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
  29. ^ "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
  30. ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
  31. ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
  32. ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  33. ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
  34. ^ Last updated