Softpedia
 


LINUX CATEGORIES:



GLOBAL PAGES >>
NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • Linux Kernel 3.9.6 / 3....
  • Linux Kernel 3.0.82 LTS...
  • KDE Software Compilatio...
  • PulseAudio 4.0
  • Wireshark 1.10.0
  • NetworkManager 0.9.8.2
  • LibreOffice 3.6.6 / 4.0...
  • SystemRescueCd 3.7.0
  • Linux Kernel 3.10 RC6
  • Ubuntu Tweak 0.8.5
  • Home > Linux > System > Monitoring

    OSSEC HIDS 2.7

    Download button

    Downloads: 2,166  View global page NEW!  Tell us about an update
    User Rating:
    Rated by:
    Good (3.4/5)
    22 user(s)
    Developer:

    License / Price:

    Last Updated:

    Category:
    Daniel B. Cid | More programs
    GPL v3 / FREE
    November 20th, 2012, 15:12 GMT [view history]
    ROOT / System / Monitoring

     Read user reviews (0)  Refer to a friend  Subscribe

    OSSEC HIDS description

    An open source host-based intrusion detection system

    OSSEC is an a free and open-source Host-based Intrusion Detection System that allows you to perform log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

    OSSEC is cross-platform and it works on Mac OS X, Windows and Linux.

    Product's homepage

    What's New in This Release: [ read full changelog ]

    Installation:

    · Add hybrid mode – allows the same host to be both a server and an agent, useful for multi-tier OSSEC deployment.
    · Add manage_agents -f option for bulk generation of client keys from an input file.
    · During Agent installation, allow the OSSEC server to be specified using hostname instead of IP.

    Syscheck:

    · Add prelinking support – reduce confusion when a file change is the result of prelinking.

    Rootcheck:

    · Add fine-grained configuration control – allows you to turn ON/OFF individual rootcheck tasks for more efficiency and flexibility. The default is all ON.

    Log monitoring/analysis:

    · Add GeoIP lookup support – allows geographical city names to be associated with IP addresses in OSSEC alerts, for more intelligent correlation.

    Alert options and syslog output:

    · Add syscheck MD5/SHA1 sum to alerts for easier integration with third-party file signature checking.
    · Support JSON and Splunk formats in syslog output.

    Rules and other notable changes/fixes:

    · Windows 2000 logs support has been deprecated (but will probably still work fine). Vista and Windows Server 2008 logs are now officially supported.
    · Windows registry syscheck alert level has been reduced from 7 to 5 to reduce unnecessary noise from alerts which do not indicate a compromise.
    · Update decoders include: PIX, auditd, apache, pam, php.
    · Many updated rules, such as new checks for vulnerable web apps exploitation attempts.
    · Update rootcheck rules.
    · ossec-client.sh now allows for ‘reload’, in addition to ‘restart’
    · Many bug fixes…

    · LICENSE text updated by adding exception clause for OpenSSL, while OSSEC is still under GPLv2

      


    TAGS:

    intrusion detection | log analysis | rootkit detection | OSSEC | HIDS | intrusion

    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM