Host Intrusion Detection
Changelog...The host intrusion detection directory contains software which provides integrity checks on information of various types. The failure of an integrity check is a useful indicator of possible system intrusion or tampering.
- AIDE
AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire which uses a configuration file, a database and a number of message digest algorithms to carry out integrity checks on file contents, file attributes etc.
Browse: HTTP / FTP / HOMEPAGE
- ifstatus
ifstatus is a tool that will generate alerts about network interfaces that have been placed in promiscuous mode.
Browse: HTTP / FTP / HOMEPAGE
- Integrit
Integrit is another alternative to tripwire and aide that works by generating a database of cryptographic hashes of a "known-good" system for comparison at some later stage to determine whether an intruder has modified the files on the system in any way.
Browse: HTTP / FTP / HOMEPAGE
- Osiris
Osiris is a file integrity verification system that can be used to monitor changes to a file system over time. Osiris consists of a pair of applications, osiris and scale. The first application, osiris, is used to collect specific data from the local filesystem and store that data into a database. The second application, scale, is then used to analyze, and/or compare the differences between two databases.
Browse: HTTP / FTP / HOMEPAGE
- Sentinel
Sentinel is a fast file/drive scanning utility similar to the Tripwire and Viper.pl utilities available. It uses a database similar to Tripwire, but uses a RIPEMD-160bit MAC checksumming algorithm (no patents) which is more secure than the patented MD5 128 bit checksum.
Browse: HTTP / FTP / HOMEPAGE
- sxid
sxid tracks any changes in your s[ug]id files and folders. If there are any new ones, ones that aren't set any more, or they have changed bits or other modes then it reports the changes. It also tracks s[ug]id files by md5 checksums. This helps detect if a root kit has been installed which would not show under normal name and permissions checking. Directories are tracked by inodes.
Browse: HTTP / FTP / HOMEPAGE
- TARA
Tiger Analytical Research Assistant (TARA) is an upgrade to the TAMU 'tiger' program. tiger was a set of scripts that scan a Un*x system looking for security problems, in the same fashion as Dan Farmer's COPS.
Browse: HTTP / FTP / HOMEPAGE
- Tripwire
Tripwire is a tool that checks to see what has changed on your system. The program monitors key attributes of files that should not change, including binary signature, size, expected change of size, etc. The hard part is doing it the right way, balancing security, maintanence, and functionality.
Browse: HTTP / FTP / HOMEPAGE
Browse this directory with: HTTP / FTP
(Note: This list of software and information available at Wiretapped is not exhaustive. Users are encouraged to browse and search the archive and read any available "-README.txt" files that are available.)
Questions / Suggestions:
Should you have any questions regarding Wiretapped or suggestions for additional software or material that we can mirror, please send an email to web[at]wiretapped.net
$Id: host-intrusion-detection.html,v 1.16 2004/09/13 12:59:37 gbayley Exp $