Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2001 > August 2001

Freeware Intrusion Detection Tools

Ido Dubrawsky

Firewalls and access control lists were once thought to be the ultimate solutions in preventing network intrusion. Unfortunately, neither tool provides the capability to respond to or provide real-time detection of an intrusion attempt. This is the gap that an Intrusion Detection System (IDS) fills. An IDS provides continual real-time or near-real-time monitoring of a host or a network.

Intrusion detection systems can be divided into two primary categories: network-based and host-based. Network-based IDS tools monitor network traffic on the local LAN, analyzing traffic that "fits" a known signature for a given exploit, and then notifies the proper contacts of its findings. Host-based IDS tools provide detection of an intrusion on a system within the network. Although the ideal case would be to prevent a system intrusion from happening, the fact is that even with a network IDS in place, it is still possible for an attacker to find ways around it. If that happens, a host-based IDS may be able to determine whether the attacker has succeeded in penetrating a given system.

Network-based IDS tools come in two forms: real-time and near-real-time. Real-time network-based IDS report suspicious traffic as soon as it is detected on the wire. Near-real-time IDS work by gathering network traffic and then at a predetermined time interval (such as once an hour) provide an analysis of the previous interval’s data. One of the benefits of real-time IDS is the capability to respond to an attack as it is happening. Near-real-time IDS also provide sufficient notification of an attack in progress.

Host-based IDS monitor system files (such as wtmp/utmp on UNIX systems) and log files as well as check the integrity of system binaries to determine whether an intrusion has occurred.




MarketPlace

Villanova University Six Sigma & IT Certificate Programs
100% Online programs in Six Sigma, IS Security, CISSP Prep, Business Analysis, Proj. Mgmt. and more!

Flowcharts from C/C++ code -- Free trial download
Understand C/C++ code in less time. A new team member ? Inherited legacy code ? Get up to speed faster with Crystal Flow for C/C++. Code-formatting improves readability. Flowcharts are integrated with code browser. Export flowcharts to Visio.

Discover WinDev 11 RAD
and develop 10 times faster ! ALM, IDE, .Net, PDF, 5GL, Database, 64-bit, etc. Free Express version

Domain Name Registrations, Web Hosting, Email
Pay less for Domain Names, Increase your company's bottom line - get a raise. Accredited domain name registrar, ZippyNames.us : Discount bulk transfers, email, webhosting, dedicated servers. Earn money as a domain name reseller - better discounts!

Wanna see your ad here?