Host-based intrusion detection system comparison
Comparison of host-based intrusion detection system components and systems.
Free and open-source software
As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.
Package | Updated | Ubuntu Official Repositories | CentOS Official Repositories | File | Network | Logs | Config | Sane defaults | Notes |
---|---|---|---|---|---|---|---|---|---|
Wazuh (OSSEC fork) | 2020 | No[1] | No[2] | Yes | Yes | Yes | Yes | ||
OSSEC | 2019 | No[3] | No[4] | Yes | Yes | Yes | Yes | ||
Samhain | 2019 | Yes[5] | No | Yes | No | Partial[6] | No | ||
Snort | 2018 | Yes[7] | No[8] | No | Yes | No | |||
chkrootkit | 2017 | Yes[9] | No | Yes | No | Partial[10] | |||
rkhunter | 2018 | Yes[11] | Yes[12] | Yes | No | No | Yes | Yes | Ubuntu 18.04 LTS has some problems. |
unhide[13] | 2012 | Yes[14] | Yes[15] | No | No | No | proc ps compare | ||
Sguil | 2017 | No | No | No | Yes | No | |||
Logwatch[16] | 2017 | Yes[17] | Yes[18] | No | No | Yes | No | ||
Logcheck[19] | 2017 | Yes[20] | Yes[21] | No | No | Yes | No | ||
Epylog[22] | 2014 | Yes[23] | Yes[24] | No | No | Yes | |||
SWATCH[25] | 2015 | Yes[26] | Yes[27] | No | No | Yes | |||
sagan | 2018 | Yes[28] | No | No | No | Yes | |||
aide | 2019 | Yes[29] | Yes[30] | Yes | No | No | No | ||
tripwire | 2018 | Yes[31] | Yes[32] | Yes | No | No | |||
Proprietary software
Package | Year[33] | Linux | Windows | File | Network | Logs | Config | Notes |
---|---|---|---|---|---|---|---|---|
Lacework | 2018 | Yes | No | Yes | Yes | Yes | Yes | |
Verisys | 2018 | Yes | Yes | Yes | Yes | Yes | ||
Nessus | 2017 | Yes | Yes | Yes | ||||
Atomicorp | 2019 | Yes | Yes | Yes | Yes | Yes | Yes | Commercially enhanced version of OSSEC |
gollark: I'm responding to TF3, not you.
gollark: That's not exactly true (humans are not anything like rational [WHATEVER NEUROCHEMICAL] maximizers), and even if they *were* it wouldn't be very helpful since the processes involved are intractably complex.
gollark: Sometimes I move from my chair to retrieve food and such.
gollark: It feels awesome to have wanted to vomit? How?
gollark: I mean, not that weird because US, but weird.
References
- "Installing Wazuh in Debian". WAZUH. Retrieved 2020-02-13. Wazuh for Debian Based systems
- "Installing Wazuh in CentOS/RHEL/Fedora". WAZUH. Retrieved 2020-02-13. Wazuh for RHEL/Fedora Based systems
- "Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems
- "Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
- "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
- Last
- "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
- "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
- "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
- lastlog, wtmp, utmp, wtmpx
- "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
- "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
- "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
- "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
- "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
- "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
- "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
- "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
- "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
- "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
- "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
- "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
- "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
- "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
- "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
- "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
- "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
- "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
- "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
- "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
- "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
- "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
- Last updated
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.