1 |
On Sat, 2003-06-14 at 03:30, Daniel Struck wrote: |
2 |
> Hello, |
3 |
> |
4 |
> I was just surfing around and found an interesting IDS: |
5 |
> |
6 |
> Prelude Hybrid IDS |
7 |
> (http://www.prelude-ids.org/) |
8 |
> |
9 |
> "Prelude is a new innovative Hybrid Intrusion Detection system designed to be very modular, distributed, rock solid and fast." |
10 |
> |
11 |
> Interesting facts about this IDS: |
12 |
> |
13 |
> " |
14 |
> we try to retrieve the "stimuli" and responses eventually associated to attacks at network level or at system level |
15 |
> ... |
16 |
> Centralizing, Archiving, and Normalizing logs in a secure way |
17 |
> ... |
18 |
> in practice we have as many sensors as possible (Prelude-NIDS, Centralized Syslogs, ...) deployed on the network which send their alerts to Security Managers. |
19 |
> ... |
20 |
> Counter-measure agents are generic agents run on the machines which must react in case of an attack. |
21 |
> ... |
22 |
> Libsafe is a preloadable library (through LD_PRELOAD directive or using an entry in /etc/ld.so.conf) which protect a program against the exploitation of vulnerabilities like buffer-overflows of bogus format string. |
23 |
> " |
24 |
> |
25 |
> |
26 |
> So, I would be interested: |
27 |
> |
28 |
> - Are there any efforts made to adapt Prelude-IDS to gentoo, maybe in relation with gentoo-hardened? |
29 |
|
30 |
I have ebuilds submitted to bug.gentoo.org and even better and updated |
31 |
ones in my local CVS repository (keep forgetting to submit them). |
32 |
|
33 |
> - Is anyone already using Prelude-IDS on gentoo? |
34 |
|
35 |
Yes, and I am already doing that. |
36 |
|
37 |
Thanks for the interest, I will update my bugs now... ;) |
38 |
|
39 |
(search for bugs submitted by michael [at] ayeka [dot] dyndns [dot] org |
40 |
to get them, or bug me privately ;) ) |
41 |
|
42 |
Best regards |
43 |
Michael Boman |
44 |
|
45 |
-- |
46 |
Michael Boman |
47 |
Security Architect, SecureCiRT Pte Ltd |
48 |
http://www.securecirt.com |