
Top : Computers : Security : Intrusion Detection Systems : Products and Tools :
Open Source
Websites
A free lightweight network intrusion detection system for UNIX and Windows.
http://www.snort.org/
Powerful PHP-based data analysis tool for network security events captured by many common IDS tools, including snort and tcpdump.
http://www.andrew.cmu.edu/~rdanyliw/snort/snortacid.html
AIDE is a file integrity checker that supports regular expressions. Licensed with GPL.
http://www.cs.tut.fi/~rammer/aide.html
Provides open source application to check for presence of rootkits installed on Linux/Unix machines. Links to security related sites.
http://www.chkrootkit.org/
Experimental intrusion detection system and reference monitor designed to run at application level. For Linux. GPL/LGPL.
http://jade.cs.uct.ac.za/idsa/
A single compilation of source, binaries, scripts and whitepapers on intrusion prevention systems. The aim is to quickly establish a working IPS within minutes.
http://lak-ips.sourceforge.net/
LIDS is an enhancement for the Linux kernel written by Xie Huagang and Philippe Biondi. It implements several security features that are not in the Linux kernel natively. Some of these include: mandatory access controls (MAC), a port scan detector, file protection (even from root), and process protection.
http://www.lids.org
Intrusion Reporting and Response. Users forward firewall logs that are aggregated and analysed to identify incidents that are reported to the responsible party.
http://www.mynetwatchman.com/
A complete intrusion detection system created with well known open-source tools. Implemented using a custom RedHat 7.2 distribution and available for download as a stand-alone ISO image.
http://www.ids.belbone.be
Network-IDS that detects and stops DoS/DDoS attacks by using real-time Cisco NetFlow data.
http://panoptis.sourceforge.net
Prelude is a new innovative hybrid Intrusion Detection system designed to be very modular, distributed, rock solid and fast.
http://www.prelude-ids.org
Perl-based log analysis tool that summarizes network security events from any native snort database format.
http://jeremy.chartier.free.fr/snortalog/
Systrace enforces system call policies for applications by interactively constraining the application's access to the system (*bsd and linux). Systrace is able to monitor daemons on remote machines and generate warnings at a central location.
http://www.citi.umich.edu/u/provos/systrace/
Shadow is an intrusion-detection system from the Naval Surface Warfare Center, shows promise in detecting previously unknown attacks for which no known detection signatures exist.
http://www.ists.dartmouth.edu/IRIA/projects/d_shadow.htm
sLink consists of a daemon and a suite of cgi programs which provide a web administration interface to an EDM/BOSCH Solution16 Alarm Panel.
http://slink.sourceforge.net
QuIDScor is an Open Source project demonstrating the value in correlating information between Intrusion Detection Systems (such as Snort) and vulnerability assesment and management platforms such as QualysGuard.
http://quidscor.sourceforge.net
Firestorm is a high-performance GPL-licensed network intrusion detection system (NIDS). Features include being fully pluggable, easily configurable, and an extremely scalable signature engine.
http://www.scaramanga.co.uk/firestorm/
An advanced passive OS/network fingerprinting utility for use in IDS environments, honeypots environments, firewalls and servers.
http://lcamtuf.coredump.cx/p0f.shtml
Open-source GPL rootkit scanner for Unix-like systems. Scans for rootkits, trojans, backdoors and local exploits. Tests include scanning of plaintext and binary files for MD5 hash comparisons, default rootkit files, binary permissions, suspect LKM/KLD module strings, and hidden files.
http://www.rootkit.nl/
A tripwire-like utility which uses MD5 to check files for modifications.
http://osiris.shmoo.com/
VXE is an open source Intrusion Prevention System intended to protect Unix subsystems (daemon protection) from known and unknown network intrusion threats.
site exerpt
Linux security system. VXE X security is that superuser can do with system anything he wants. There are programs (daemons) which work with superuser privilegies, for example popd, sendmail, and accessible from network (Internet/Intranet There could be bugs in any program, so intruder connects...Bleeding Snort was a response to the need for a centralized spot for Snort Signatures to be aggregated and maintained. Contains snort rules for malware, viruses, and "0day" exploits.
http://www.bleedingsnort.com
fail2ban is a POSIX/Linux tool used to ban IP addresses that generate too many password failures. ssh, iptables, ipfwadm and ipfw are currently supported.
http://sourceforge.net/projects/fail2ban/
SnortSMS is a highly configurable PHP-based application used to remotely control, administer, and monitor multiple Snort-based IDS sensors.
http://snortsms.servangle.net/
The Fairly Fast Packet Filter (FFPF) is a network monitoring framework for Linux. FFPF achieves high throughput by pushing computationally intensive tasks to the kernel or even network processors and by minimising packet copying.
http://ffpf.sourceforge.net/
IDABench is a pluggable framework for intrusion analysis built upon the Naval Surface Warfare Center, Dahlgren Division's SHADOW versions 1.7 and 1.8. Scripts can be extended via plugins that pass packet data to (and output from) most libpcap-based tools.
http://idabench.ists.dartmouth.edu