?
Solved

Intrusion Detection Systems

Posted on 2001-08-13
20
Medium Priority
?
247 Views
Last Modified: 2010-04-11
Would anyone be willing to share there opinions or recommendations on an Intrusion Detection System?
0
Comment
Question by:vmorales
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 15
  • 4
20 Comments
 
LVL 14

Expert Comment

by:chris_calabrese
ID: 6381767
The leading Network IDS contenders are ISS RealSecure, Cisco Secure IDS, Symantec NetProwler, NFR, and Snort.  The leading Host IDS contenders are ISS RealSecure, Tripwire, Symenatec Intruder Alert, and PentaSafe.  (note, this is off the top of my head).

But, which of these products or combination of products is right for you depends on...

Whether you want Network IDS, Host IDS, or both.
How much money you have to spend.
How many network segements you want to sniff (NIDS).
How many hosts and what OS they are (HIDS).
Whether you want integration with some other bits like CheckPoint firewalls or Cisco routers.
0
 

Author Comment

by:vmorales
ID: 6381963
0
 

Author Comment

by:vmorales
ID: 6382118
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 

Author Comment

by:vmorales
ID: 6382126
0
 

Author Comment

by:vmorales
ID: 6382127
0
 

Author Comment

by:vmorales
ID: 6382141
0
 

Author Comment

by:vmorales
ID: 6382143
0
 

Author Comment

by:vmorales
ID: 6382146
0
 

Author Comment

by:vmorales
ID: 6382154
0
 

Author Comment

by:vmorales
ID: 6382235
0
 

Author Comment

by:vmorales
ID: 6382239
0
 

Author Comment

by:vmorales
ID: 6382243
0
 
LVL 3

Expert Comment

by:erikdr
ID: 6383405
Look at www.networkcomputing.com.

They very recently (now on homepage) did an extensive 10-brand test of ISS systems in a real lab. And managed e.g. to blow up eTrust (it required 4,000 times the power of one Pentium III to monitor their nodes) and Symantec NetProwler (could only handle 1 subnet). Top came out Enterasys and Cisco.

Hope this helps,

<Erik> - The Netherlands
0
 

Author Comment

by:vmorales
ID: 6384404
I basically need as system that would sit between the router and the firewall that can support reporting, paging, etc. Network IDS would seem to be the solution here. How much money? Free or less than $10,000
0
 

Author Comment

by:vmorales
ID: 6384410
I have been looking at Shadow and Dragon. I curious if Shadow can be deployed on an OpenBSD box?
0
 
LVL 14

Expert Comment

by:chris_calabrese
ID: 6384415
Given the small network infrastructure and the low budget, you're probably best off going with Snort (which is free) if you have the *nix expertise to use it properly.  Otherwise look at Symantec NetProwler, which runs on NT.
0
 

Author Comment

by:vmorales
ID: 6384439
Chris,

We have also looked at Snort. I am curious as to your opinion of Shadow and Dragon. And why Snort over Shadow and Dragon. "No pun intended" :)
0
 
LVL 14

Accepted Solution

by:
chris_calabrese earned 200 total points
ID: 6384473
Snort seems to be getting the most mind-share these days and therefore has the best ancilliary tools and signature database.

Dragon is not too far behind, though.

Shadow seems like it's pretty dead at this point, since all the Shadow folks from the old Shadow team at Naval Surface Warfare Center are now working either for Cisco or the SANS Institute.
0
 

Author Comment

by:vmorales
ID: 6384523
Will snort run on an OpenBSD box?
0
 
LVL 14

Expert Comment

by:chris_calabrese
ID: 6384558
Yes.  My office mate runs it on OpenBSD and claims it runs best there.
0

Featured Post

Ransomware Attacks Keeping You Up at Night?

Will your organization be ransomware's next victim?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with our Ransomware Prevention Kit!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Petya-like ransomware attack served a big blow to hundreds of banks, corporations and government offices The Acronis blog takes a closer look at this damaging worm to see what’s behind it – and offers up tips on how you can safeguard your…
Hey fellow admins! This time, I have a little fairy tale for you. As many tales do, it starts boring and then gets pretty gory. I hope you like it. TL;DR: It is about an important security matter, you should read it if you run or administer Windows …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question