Internet.com ISP-Planet
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us














ISP Technology

 

General

Security Tools for the Budget Conscious ISP, Part III: Host Intrusion Detection Systems

by Lisa Phifer
VP Core Competence, Inc.
[February 6, 2004]
Email a colleague

Host Intrusion Detection Systems
Most organizations build a layered defense that combines NIDS with Host Intrusion Detection Systems (HIDS). A HIDS keeps a watchful eye on what's happening on its computing platform, detecting and alerting you to signs of attack like overwriting or deletion of system files, suspicious processes, and unusual user activity.

Host-resident personal firewall software could be considered one aspect of HIDS. Products like ZoneLabs ZoneAlarm and Norton Personal Firewall can block suspicious incoming traffic and stop any process not on the authorized application list from sending traffic. For example, if a virus overwrites IE with a trojan horse, products like these can detect the executable has been modified and block network access.

Some HIDS are integrity management systems that repeatedly take cryptographic snapshots of OS and application and configuration files. Comparing these snapshots against known-good reference points can detect attempts to deface a website, add a new user, change file permissions, etc.. Other HIDS are system activity monitors that watch for errors or event sequences that might indicate a server is under attack or being used as a springboard to compromise other systems.

As with NIDS, there are many different approaches, and some products offer Host Intrusion Prevention in addition to Host Intrusion Detection. For a complete solution, you may need to combine several tools, and you should expect to spend time baselining each protected server. Here is an illustrative, non-exhaustive list of HIDS products:

A sampling of freely-available HIDS tools includes:

  • AIDE (Advanced Intrusion Detection Environment) is an open source file integrity monitor for *NIX systems.

  • Fcheck is a Perl-based open source tool that uses system snapshots to detect file system changes (modifications, deletions) on Win32 and *NIX hosts.

  • FTimes is an open source system baselining tool that can be used in single-system or client-server modes, and can be compiled on Win32 and most *NIX platforms.

  • Integrit is a compact open source file system integrity checker for POSIX-compliant systems.

  • MD5deep is a checksum-based cross-platform file integrity checker freely available in Win32 binary and Windows/*NIX open source formats. To view sample md5deep output, click here.

  • OSIRIS is an open source HIDS that detects any change made to file systems by comparing periodic snapshots. OSIRIS runs on Windows and *NIX hosts.

  • Samhain is an open source HIDS for *NIX detects file modification and spots SUID executables and root kits on Linux and FreeBSD. Events can be consolidated and viewed through a companion console tool, Beltane.

  • SWATCH is a Perl-based "watchdog" program that monitors any log file for specified strings that indicate possible intrusion and takes corresponding action (e.g., execute program, call pager, e-mail sysadmin).

  • Tripwire, a popular system integrity checker, is freely-available in open source and RedHat RPM formats. Tripware sells commercial products for other *NIX and Win32 platforms.

.

Security Tools for the Budget Conscious ISP, Part III:
Host Intrusion Detection Systems

 

 

ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly

Best of ISP-Planet

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Whitepapers and eBooks

Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
IBM Solutions Brief: Go Green With IBM System xTM And Intel
HP eBook: Simplifying SQL Server Management
IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
Microsoft PDF: Top 10 Reasons to Move to Server Virtualization with Hyper-V
Microsoft PDF: Six Reasons Why Microsoft's Hyper-V Will Overtake Vmware
Microsoft Step-by-Step Guide: Hyper-V and Failover Clustering
Intel PDF: Quad-Core Impacts More Than the Data Center
Intel PDF: Virtualization Delivers Data Center Efficiency
Go Parallel Article: PDC 2008 in Review
Microsoft PDF: Top 11 Reasons to Upgrade to Windows Server 2008
Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
  PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
Go Parallel Article: Q&A with a TBB Junkie
IBM Whitepaper: Innovative Collaboration to Advance Your Business
Internet.com eBook: Real Life Rails
IBM eBook: The Pros and Cons of Outsourcing
Internet.com eBook: Best Practices for Developing a Web Site
IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
HP eBook: Guide to Storage Networking
MORE WHITEPAPERS, EBOOKS, AND ARTICLES