IDS mailing list archives

Re: System call based IDS for linux?


From: Jose Nazario <jose () monkey org>
Date: Mon, 27 Mar 2006 16:32:45 -0500 (EST)

On Sun, 26 Mar 2006, Nomellames nunca wrote:

Is there any system call based IDS for Linux? There exist an a lot of
research on the field, but I failed to find any package which I can give
a try. If anybody knows any project (stable or not) , I will truly
appreciate it.

LIDS?
http://www.lids.org/node/9

Systrace? (new 1.6 release improves Linux support greatly)
http://www.citi.umich.edu/u/provos/systrace/linux.html

those what you mean?

________
jose nazario, ph.d.                     jose () monkey org
http://monkey.org/~jose/                http://infosecdaily.net/
                                        http://www.wormblog.com/

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------


Current thread: