IDS mailing list archives

Re: Host Based IDS Recommendations?


From: Brian Wotring <brian () shmoo com>
Date: Fri, 10 Oct 2003 23:47:08 -0600


You might want to take a look at Osiris, it supports Windows NT/2K/XP:

    http://osiris.shmoo.com

On Oct 10, 2003, at 12:40 AM, Alvin Wong wrote:

Hi,

I would like to find out for Windows boxes if there are any
recommendations for Host based IDS, i know that for unix there is AIDE,
linux, tripwire. What are the solutions for Windows machines? Would
running a software IDS that is capable of monitoring and protecting the
file systems a la tripwire with signed hashes kept in removable media be sufficient? If there are, what are the usual suspects for host based IDS
that is used prevalently in industry? I'm hoping for both free and
commercial solutions

Regards,
Alvin


----------------------------------------------------------------------- ----
Captus Networks IPS 4000
Intrusion Prevention and Traffic Shaping Technology to:
 - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
 - Automatically Control P2P, IM and Spam Traffic
- Precisely Define and Implement Network Security & Performance Policies
FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
----------------------------------------------------------------------- ----


--
    Brian Wotring ( brian () shmoo com )
    PGP KeyID: 0x9674763D


---------------------------------------------------------------------------
Captus Networks IPS 4000
Intrusion Prevention and Traffic Shaping Technology to: - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
- Automatically Control P2P, IM and Spam Traffic
- Precisely Define and Implement Network Security & Performance Policies
FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
---------------------------------------------------------------------------


Current thread: