Host-based intrusion detection system comparison

Comparison of host-based intrusion detection system components and systems.

Free and open-source software

As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.

Package Updated Ubuntu Official Repositories CentOS Official Repositories File Network Logs Config Sane defaults Notes
Wazuh (OSSEC fork) 2020 No[1] No[2] Yes Yes Yes Yes
OSSEC 2019 No[3] No[4] Yes Yes Yes Yes
Samhain 2019 Yes[5] No Yes No Partial[6] No
Snort 2018 Yes[7] No[8] No Yes No
chkrootkit 2017 Yes[9] No Yes No Partial[10]
rkhunter 2018 Yes[11] Yes[12] Yes No No Yes Yes Ubuntu 18.04 LTS has some problems.
unhide[13] 2012 Yes[14] Yes[15] No No No proc ps compare
Sguil 2017 No No No Yes No
Logwatch[16] 2017 Yes[17] Yes[18] No No Yes No
Logcheck[19] 2017 Yes[20] Yes[21] No No Yes No
Epylog[22] 2014 Yes[23] Yes[24] No No Yes
SWATCH[25] 2015 Yes[26] Yes[27] No No Yes
sagan 2018 Yes[28] No No No Yes
aide 2019 Yes[29] Yes[30] Yes No No No
tripwire 2018 Yes[31] Yes[32] Yes No No

Proprietary software

Package Year[33] Linux Windows File Network Logs Config Notes
Lacework 2018 Yes No Yes Yes Yes Yes
Verisys 2018 Yes Yes Yes Yes Yes
Nessus 2017 Yes Yes Yes
Atomicorp 2019 Yes Yes Yes Yes Yes Yes Commercially enhanced version of OSSEC
gollark: I'm responding to TF3, not you.
gollark: That's not exactly true (humans are not anything like rational [WHATEVER NEUROCHEMICAL] maximizers), and even if they *were* it wouldn't be very helpful since the processes involved are intractably complex.
gollark: Sometimes I move from my chair to retrieve food and such.
gollark: It feels awesome to have wanted to vomit? How?
gollark: I mean, not that weird because US, but weird.

References

  1. "Installing Wazuh in Debian". WAZUH. Retrieved 2020-02-13. Wazuh for Debian Based systems
  2. "Installing Wazuh in CentOS/RHEL/Fedora". WAZUH. Retrieved 2020-02-13. Wazuh for RHEL/Fedora Based systems
  3. "Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems
  4. "Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
  5. "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
  6. Last
  7. "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
  8. "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
  9. "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
  10. lastlog, wtmp, utmp, wtmpx
  11. "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
  12. "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
  13. "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
  14. "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
  15. "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
  16. "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
  17. "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
  18. "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
  19. "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
  20. "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
  21. "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
  22. "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
  23. "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
  24. "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
  25. "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
  26. "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
  27. "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
  28. "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
  29. "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
  30. "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
  31. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
  32. "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
  33. Last updated
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.