Re: intrusion detection



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

<snip>

In the host-based category, I'm aware of two -- there's the
samhain/yule/beltane family, which are really one intrustion
detection apparatus. Samhain is the daemon that runs on the
clients being monitored, yule is the server that maintains
the (remote from the client) database, and beltane is the
web app you can use to monitor changes. Beltane costs
a small amount of money, and the others are free (as in beer).

<snip>

I can recommend ossec[0]. It is a great little host IDs, which works
great out of the box. :)

- --
Cheers,
Julian De Marchi
- --
OpenNIC user - http://www.opennicproject.org/ | http://www.opennic.glue
Support OpenNIC, become a member today!
- --
Please avoid sending me Word or PowerPoint attachments.
See http://www.gnu.org/philosophy/no-word-attachments.html

0 - http://www.ossec.net/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD4DBQFJB8w1fM8nSo1lmBQRAl2QAJ9Cqw8OIfuSMjGVW5N50oEdIrCGAQCY+W46
hQ1QecZiNbjGKCZ3+Nfh1Q==
=3Z5B
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: Reducing wastage of screen real estate in gnome
    ... Actually, the monitor is dated August 23, 1993. ... room to have more than one window open, its nice to have the task bar. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Reducing wastage of screen real estate in gnome
    ... I get along just fine with icewm. ... But isn't that 9" monitor a VT520? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: openSUSE 11.1, nvidia 9600 KO - resolution problems....again!
    ... to the "monitor" section of the xorg.conf file? ... This option forces the X driver to use the EDID specified in a file ... list of display names and filename pairs. ...
    (alt.os.linux.suse)
  • Re: Tech question - interface between receiver and central station software
    ... I agree with the benefits of being local - ADT is losing a lot of clients ... > remote terminal we monitor for another company, ... > We have a few IRFast clients, very handy format. ... >> Patriot guy, who asked us more question than we asked him. ...
    (alt.security.alarms)
  • Re: Unable to browse one child domain from another
    ... You can try posting it elsewhere, however most if not all of the folks that monitor and respond in this group, also monitor the other groups. ... As I've implied, WINS is the answer for multi-subnet browsing to allow consitency, whether for apps or browsing in general, especially if you have VPN access clients on a separate VPN subnet, which does not work with DirectSMB browsing. ... I was under the impression that the browse list was entirely dependant on compilation of client announcements (by the Master Browser), and entirely dependant on NetBIOS / Broadcast. ...
    (microsoft.public.windows.server.dns)