Intrusion detection systems

I need recommendation for Intrusion Detection system where it can report and tell you what files has been changed and/or lock it down and prevent changing.  I used Snort a while back and wonder if this is a good product or need any alternatives.
Please advice.
LVL 17
Tiras25Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Kevin HaysIT AnalystCommented:
Well lots of people have probably used snort since it's open source.  You have winsnort also for windows if i'm not mistaking.

You should have a IPS along with the IDS to have a solid security foundation.  The rules you apply in the IDS goes a long way in making it more secure and detailed also.

There are also enterprise class IDS/IPS out there also, but for most snort is good.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Tiras25Author Commented:
Bystorm product.  Anyone heard of that?
http://www.bystorm.com/products-overview.html

====================
FileSure for Windows
FileSure for Windows leverages patent-pending technology that operates outside of native-Windows ACLs (Access Control Lists) to provide file access auditing, file access control, and data loss protection.
FileSure is a policy-based product (rules) that is easily configured and managed from a single location. FileSure complements your existing user and group permissions and eliminates the need for you to ever touch an ACL again!
0
pand0ra_usaCommented:
You are not necessarily looking for an IDS but a Integrity checker. Windows has one built in for Microsoft specific files called sigverif. If you are looking for a comprehensive application I've used 3rd Brigade in the past that installs an agent on each machine you want to monitor. It does anti virus, firewall, HIDS (detect and/or prevent), integrity checking, and log monitoring.
0
Tiras25Author Commented:
Interesting idea.  How 'comprehensive' app would be different than sigverif from MS.  Maybe that MS tool would be just enough for me.
0
pand0ra_usaCommented:
From an integrity checker standpoint, 3rd Brigade will verify any file or folder you define whereas sigverif.exe will only do windows files that have been singed by Microsoft.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Security

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.