Jump to content

Host-based intrusion detection system comparison

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by 2a02:8388:6983:7780:ac74:845a:2859:ed7d (talk) at 04:30, 28 March 2019 (Free and Open Source software). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Comparison of host-based intrusion detection system components and systems.

As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.

Package Updated Ubuntu[1] CentOS[2] File Network Logs Config Sane defaults Notes
OSSEC 2019 Yes[3] Yes[4] Yes Yes Yes Yes
Samhain 2016 Yes[5] No Yes No Partial[6] No
Snort 2018 Yes[7] Yes[8] No Yes No
chkrootkit 2017 Yes[9] No Yes No Partial[10]
rkhunter 2018 Yes[11] Yes[12] Yes No No Yes Yes Ubuntu 18.04 LTS has some problems.[citation needed]
unhide[13] 2012 Yes[14] Yes[15] No No No proc ps compare
Sguil 2017 No No No Yes No
Logwatch[16] 2017 Yes[17] Yes[18] No No Yes No
Logcheck[19] 2017 Yes[20] Yes[21] No No Yes No
Epylog[22] 2014 Yes[23] Yes[24] No No Yes
SWATCH[25] 2015 Yes[26] Yes[27] No No Yes
sagan 2018 Yes[28] No No No Yes
aide 2019 Yes[29] Yes[30] Yes No No No
tripwire 2018 Yes[31] Yes[32] Yes No No
Package Year[33] Linux Windows File Network Logs Config Notes
Lacework 2018 Yes No Yes Yes Yes Yes
Verisys 2018 Yes Yes Yes Yes Yes
Nessus 2017 Yes Yes Yes

References

  1. ^ Repositories
  2. ^ Repositories
  3. ^ "Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems
  4. ^ "Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
  5. ^ "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
  6. ^ Last
  7. ^ "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
  8. ^ "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
  9. ^ "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
  10. ^ lastlog, wtmp, utmp, wtmpx
  11. ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
  12. ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
  13. ^ "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
  14. ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
  15. ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
  16. ^ "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
  17. ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
  18. ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
  19. ^ "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
  20. ^ "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
  21. ^ "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
  22. ^ "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
  23. ^ "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
  24. ^ "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
  25. ^ "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
  26. ^ "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
  27. ^ "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
  28. ^ "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
  29. ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
  30. ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
  31. ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  32. ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
  33. ^ Last updated