Intrusion Detection System (IDS) is an indispensable component of any plan of action for the security of an enterprise. What are Intrusion Detection systems? CERIAS stands for The Center for Education and Research in Information Assurance and Security.
“The purpose of an intrusion detection system (or IDS) is to detect unauthorized access or misuse of a computer system. Intrusion detection systems are kind of like burglar alarms for computers. They sound alarms and sometimes even take corrective action when an intruder or abuser is detected. Many different intrusion detection systems have been developed but the detection schemes generally fall into one of two categories, anomaly detection or misuse detection. Anomaly detectors keep a watch on behavior that deviates from the use of a normal system. Misuse detectors watch out for the way of action that matches up a well known attack scenario. A great deal of time and effort has been invested in intrusion detection, and this list provides links to many sites that discuss a few of these efforts”(http://www.cerias.purdue.edu/about/history/coast_resources/intrusion_detection/)
There is a sub-category of intrusion detection systems called network intrusion detection systems (NIDS). These systems monitors packets on the network wire and looks for suspicious activity. Network intrusion detection systems can monitor a large number of computers simultaneously over a network, while other intrusion detection systems can do the monitoring of only a single one.
Who is breaking into your system?
One most common misconception of software hackers is that it is usually people outside your network who break into your systems and cause mayhem. The reality, especially for corporate workers, is that insiders can and usually do cause the majority of security breaches. Insiders often impersonate people with more privileges then themselves to gain access to sensitive information.
How do intruders break into your system?
The simplest and easiest way to break in is to letting someone having a physical access to the system. Despite the best of efforts, it is often impossible to stop someone once physical access to a machine. Also, if someone has an account on a system already, at a low permission level, another way to break in is to use tricks of the trade to be rendered the privileges of higher level through the uses of holes in your system. Finally, there are many to gain access to systems even if one is working remotely. Remote intrusion techniques have become harder and more complex to fight.
How does one stop intrusions?
There are several Freeware/shareware Intrusion Detection Systems as well as commercial intrusion detection systems.
Open Source Intrusion Detection Systems
Below are a few of the open source intrusion detection systems:
AIDE (http://sourceforge.net/projects/aide) Self-described as “AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire which does the identical things as the semi-free Tripwire and more. There are many other non-paid replacements available so why create another new one? All the other replacements do not achieve the level of Tripwire. And I wanted a program that would exceed the limitations of Tripwire.”
File System Saint (http://sourceforge.net/projects/fss) – Self-described as, “File System Saint is a lightweight host-based intrusion detection system with primary focus on and ease of use.”
Snort (www.snort.org) Self-described as “Snort® is an open source network intrusion prevention and detection system that utilize a language of rule driven which combines the benefits of signature, protocol and anomaly based inspection methods. With millions of downloads to date, Snort is the most widely deployed intrusion detection and prevention technology all over the world and has become the de facto standard for the industry.”
Commercial Intrusion Detection Systems
If you are looking for Commercial Intrusion Detection Systems, here are a few of these as well:
eEye Digital Security (SecureIIS Web Server Protection)