0

Do I really need a HIDS like ossec, or will using good passwords, using a firewall, an antivirus/antimalware program, and a rootkit scanner do the job well enough?

Mark Buffalo
  • 22,498
  • 8
  • 74
  • 91
0000
  • 13
  • 1
  • 7

1 Answers1

1

HIDS is very much overkill for a home PC unless you are doing something super-sensitive. More importantly though, HIDS is reactive and to react, you have to monitor it. So the HIDS app is only a part of the solution. You need event reporting and collation and you need both eyes on the output and a way to do something if you get an event. I've seen far too many security solutions implemented that are then ignored or only checked occasionally.

In reality, the best additional security you can put on a home PC or any PC really is something that only allows whitelisted applications to run. This massively reduces the attack surface of your PC and greatly increases the complexity of an attack.

Julian Knight
  • 7,092
  • 17
  • 23