Welcome to Firewall.cx   Cisco Technical Knowledgebase
Modules
· Home
· Alternative Menu
· Amazon
· Cisco Decrypter
· Cisco Lab Partners
· Feedback
· Forums
· Max Arcade
· Private Messages
· Recommend Us
· Statistics
· Stories Archive
· Submit News
· Surveys
· Topics
· Web Links
· Your Account
 
Cisco Knowledgebase Articles
 
Site Info
Your IP: 38.107.191.113

Welcome, Anonymous
Nickname
Password

· Register
· Lost Password
Server Date/Time
31 July 2010 13:59:47 EEST (GMT +3)
 
Top Downloads
 
Gold Lab Partners


 
Firewall.cx: Forums

Firewall.cx :: View topic - IDS, EDS...
Forums Home
Forum FAQ :: Search :: Memberlist :: Usergroups
Profile :: Log in to check your private messages :: Log in

View next topic
View previous topic
Post new topic   Reply to topic
Author Message
wrath_child
New Member
New Member


Joined: Feb 10, 2003
Posts: 9
Location: Tbilisi, Georgia

PostPosted: Fri Feb 14, 2003 10:49 pm    Post subject: IDS, EDS... Reply with quote

What IDS (Intrusion detection software) and EDS (exploit detection software) is used and is recommended by forum members?

Thanks in advance
Back to top
View user's profile Send private message Send e-mail
James1830
New Member
New Member


Joined: Jul 12, 2003
Posts: 2

PostPosted: Sun Jul 13, 2003 12:56 am    Post subject: IDS, EDS... Reply with quote

I've had good luck with a product called "Snort". It has a nice web interface called "Acid" that makes quick checks a breeze.
Back to top
View user's profile Send private message Send e-mail
sahirh
Associate Editor & Security Advisor


Joined: Aug 14, 2003
Posts: 1699
Location: Mumbai, India.

PostPosted: Fri Oct 03, 2003 11:29 am    Post subject: Reply with quote

As a network based intrusion detection system, snort is considered the best
www.snort.org [i think]

As a host based IDS, I use tripwire for file integrity checking.

I'm not sure what an EDS is, could you elaborate or point out the difference..
Though I would recommend some tool that regularly scans logfiles, for example CERT has a tool that scans logs for traces that log cleanup tools leave -- an instant indication that you've got a problem. There are lots of automated log scanners out there for all platforms.

Sahir
Back to top
View user's profile Send private message Visit poster's website
Manip
Occasional Member
Occasional Member


Joined: Jan 15, 2003
Posts: 51
Location: UK

PostPosted: Fri Oct 03, 2003 8:43 pm    Post subject: Reply with quote

If you have a windows machine then BlackIce isn't bad..... Although snort isn't hard to setup, blackice is like setting up any other windows firewall (piss easy)
Back to top
View user's profile Send private message Visit poster's website
tfs
Retired Team Member


Joined: Jul 22, 2003
Posts: 521
Location: Orange County, California

PostPosted: Fri Oct 03, 2003 9:27 pm    Post subject: Reply with quote

Couldn't recommend one as I haven't used one myself. It mainly seems to deal with email security. The following link seems to be the same explanation of it. I looked at a couple of other links and they are the same article. GFI seems to be the main company that deals with it. How good it is I couldn't tell you.

http://www.gfi.com/mailsecurity/wpexploitengine.htm
_________________
Thanks,

Tom
Back to top
View user's profile Send private message
sahirh
Associate Editor & Security Advisor


Joined: Aug 14, 2003
Posts: 1699
Location: Mumbai, India.

PostPosted: Wed Oct 08, 2003 10:14 am    Post subject: Reply with quote

Blackice the firewall sucked pretty bad, in fact it even failed leaktest (www.grc.com) i don't know about blackice IDS and its capabilities. I know that sygate personal firewall has some rudimentary IDS capability.. it picks up on known attacks.
_________________
Sahir Hidayatullah.
Firewall.cx Staff - Associate Editor & Security Advisor
http://tftfotw.blogspot.com
Back to top
View user's profile Send private message Visit poster's website
tfs
Retired Team Member


Joined: Jul 22, 2003
Posts: 521
Location: Orange County, California

PostPosted: Wed Oct 08, 2003 12:00 pm    Post subject: Reply with quote

I tried using Blackice years ago and had nothing but trouble with it. I didn't know they made an IDS product.
_________________
Thanks,

Tom
Back to top
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum




smartDark Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group
 
Forums ©

© Copyright 2000-2010 Firewall.cx - All Rights Reserved

Copyright of all documents and images belonging to this site by Firewall.cx. Information contained on this site is copyrighted material.

It is illegal to copy or redistribute this information in any way without the written consent of Firewall.cx


Firewall.cx disclaims any responsibility for software and information obtained through this site or its links.


Page Generation: 0.39 Seconds