Gentoo Archives: gentoo-hardened

From: Michael Boman <michael.boman@××××××××××.com>
To: Daniel Struck <community@××××××.lu>
Cc: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Prelude Hybrid IDS
Date: Sun, 15 Jun 2003 04:13:21
Message-Id: 1055650369.29953.30.camel@r2d2.dmz1.securecirt.com
In Reply to: [gentoo-hardened] Prelude Hybrid IDS by Daniel Struck
1 On Sat, 2003-06-14 at 03:30, Daniel Struck wrote:
2 > Hello,
3 >
4 > I was just surfing around and found an interesting IDS:
5 >
6 > Prelude Hybrid IDS
7 > (http://www.prelude-ids.org/)
8 >
9 > "Prelude is a new innovative Hybrid Intrusion Detection system designed to be very modular, distributed, rock solid and fast."
10 >
11 > Interesting facts about this IDS:
12 >
13 > "
14 > we try to retrieve the "stimuli" and responses eventually associated to attacks at network level or at system level
15 > ...
16 > Centralizing, Archiving, and Normalizing logs in a secure way
17 > ...
18 > in practice we have as many sensors as possible (Prelude-NIDS, Centralized Syslogs, ...) deployed on the network which send their alerts to Security Managers.
19 > ...
20 > Counter-measure agents are generic agents run on the machines which must react in case of an attack.
21 > ...
22 > Libsafe is a preloadable library (through LD_PRELOAD directive or using an entry in /etc/ld.so.conf) which protect a program against the exploitation of vulnerabilities like buffer-overflows of bogus format string.
23 > "
24 >
25 >
26 > So, I would be interested:
27 >
28 > - Are there any efforts made to adapt Prelude-IDS to gentoo, maybe in relation with gentoo-hardened?
29
30 I have ebuilds submitted to bug.gentoo.org and even better and updated
31 ones in my local CVS repository (keep forgetting to submit them).
32
33 > - Is anyone already using Prelude-IDS on gentoo?
34
35 Yes, and I am already doing that.
36
37 Thanks for the interest, I will update my bugs now... ;)
38
39 (search for bugs submitted by michael [at] ayeka [dot] dyndns [dot] org
40 to get them, or bug me privately ;) )
41
42 Best regards
43 Michael Boman
44
45 --
46 Michael Boman
47 Security Architect, SecureCiRT Pte Ltd
48 http://www.securecirt.com

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Prelude Hybrid IDS Daniel Struck <community@××××××.lu>
Re: [gentoo-hardened] Prelude Hybrid IDS Daniel Struck <community@××××××.lu>
Re: [gentoo-hardened] Prelude Hybrid IDS Ned Ludd <solar@g.o>