Link to home
Start Free TrialLog in
Avatar of Matt_Greaves
Matt_Greaves

asked on

Host level Intrusion Detection or prevention System

I am looking for a host level intrusion detection system for 32bit and 64bit windows servers. Long story short we have an attacker who is appears to be using a dictionary attack on our servers exposed to the web. We use a RDP gateway server and I am seeing thousand of attempts to authenticate to our server. usernames like Symantec, POS, dhcp, guest, rob, kat, tony, sales, showroom, it goes on and on. I have been able to track some of the IP's down and created a firewall rule to stop them but only temporarily.  I'm not incredibly worried at the moment since we use good standards for usernames and have password policies enforced.

I would like a way to identify without a bunch of manual work the source IP and alert me. If it could actually block them without manual intervention that would be even better. I'd like to keep the cost below $5,000 if possible.

I apologize if this is posted in the wrong area, I don't think I have ever posted a question here before.
SOLUTION
Avatar of Dan Craciun
Dan Craciun
Flag of Romania image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Matt_Greaves
Matt_Greaves

ASKER

I needed a host level solution. My solution of using RDP guard solved the specific question I posted. Dan's was a great solution as well and long term is likely the better option. His solution however was not a quick fix and since I was in a position where I needed a quick fix ultimately I felt mine was the better option for the specific scenario I was faced with.