As far as I know, OSSEC is a Open Source HIDS. It's a "Detection System". I read in journals, it collect logs and flag any anomaly that had been found in a system ( e.g. Debian Server ) and do some action with it.
Some of the OSSEC's rules, there's like a possible way for prevent the anomaly for doing it action like, prevent brute force by blocking an IP for 600 seconds if the authentication failed 2 times.
Is there any rules, or some active-response command that would stop some virus or anomaly from spreading, infect and crushing our system. Is there ever any demostration regarding those condition ? where could i find it ?
what i have tried is like blocking an ip for brute force attack (FTP, SSH), but what about if the hacker are in some condition could prevent the ossec rules blocking ip, and he started to spread some unwanted files/document as known as virus ? Is there any footage or demonstration about that ?
My question, How can OSSEC handle a virus that already spreading ? OSSEC is just like detect the anomaly and do some action. Is it possible ?