OSSEC
This article is licensed under the GNU Free Documentation License. It uses material from the Wikipedia article "OSSEC"
.

content
OSSEC
Developed by Daniel B. Cid
Latest release 1.6 / Sep 02, 2008
OS Cross-platform
Type Security / HIDS
License GNU GPL v3
Website www.ossec.net

OSSEC is a free, open source host-based intrusion detection system. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, time-based alerting and active response. It provides intrusion detection for most operating systems, including Linux, OpenBSD, FreeBSD, Mac OS X, Solaris and Windows. It has a centralized, cross-platform architecture allowing multiple systems to be easily monitored and managed. It was written by Daniel B. Cid and made public in 2004.

On June 2008 the OSSEC project and all the copyright owned by the project leader, Daniel B. Cid, were acquired by Third Brigade, Inc. They promised to continue to contribute to the open source community and extend commercial support and training to the OSSEC open source community.

Contents

Software Components

OSSEC consists of a main application, a Windows agent, and a web interface software component.

  • Main Application: The main application, OSSEC, is required for distributed network or stand-alone installations. It is supported by Linux, Solaris, BSD, and Mac environments.
  • Windows Agent: The Windows Agent is provided for Microsoft Windows environments. An installation of the main application configured for server mode is required to support the Windows Agent.
  • Web Interface: A separate web interface application provides a graphical user interface. Like the main application, it is supported by Linux, Solaris, BSD, and Mac environments.

Capabilities

OSSEC has a very strong log analysis engine, being able to correlate and analyze logs from multiple devices and formats. The following are currently supported:

  • NIDS:
    • Cisco IOS IDS/IPS module
    • Snort IDS (snort full, snort fast and snort syslog)
  • Windows event logs (logins, logouts, audit information, etc)
  • Windows Routing and Remote Access logs
  • Generic unix authentication (adduser, logins, etc)

References

External links

© jGames.co.uk 2007 (some content from Wikipedia under GDL ) !-- ValueClick Media 468x60 and 728x90 Banner CODE for jgames.co.uk -->
Your Ad Here