IDS mailing list archives

RE: Open Source IDS Solution?


From: "McKinley, Jackson" <Jackson.McKinley () team telstra com>
Date: Fri, 26 Aug 2005 13:47:51 +1000

 Personally I think snort is the best sensor ive seen, add that with the
speed that.  The difference I think is what you do with your alerts
(Correlation technology).

There are a number of "Open source" correlation engines out there.  One
that ive always liked was Open Aanval by remote assesment.  They have
started to sell it how but from memory there is still an open source /
free limited version version.  Its called Aaanval or something..
www.aanval.com


-----Original Message-----
From: Persio Pucci [mailto:ppucci () multirede com br] 
Sent: Friday, 26 August 2005 3:58 AM
To: focus-ids () securityfocus com
Subject: Open Source IDS Solution?

Hello folks,

I am working on a study to deploy some IDS over my company's network,
and I would like to know what GOOD and RELIABLE Open Source IDS are out
there. I could not find a comparative sheet of any kind (or at least,
not a recent one) so I am asking you guys if you have any good ideas. I
already know Snort. What are the other ones?

Thank you for your help!

- Persio

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------


Current thread: