OSSIM as IDS

View: New views
8 Messages — Rating Filter:   Alert me  

OSSIM as IDS

by online_preeti :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Dear All,

Is that anyone has worked on OSSIM as an open source for intrusion detection?

Regards
Preeti

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Re: OSSIM as IDS

by dkny :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Good, but a lot of work to get it in place.
David

Quoting online_preeti@...:

> Dear All,
>
> Is that anyone has worked on OSSIM as an open source for intrusion detection?
>
> Regards
> Preeti
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to  
> http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
> to learn more.
> ------------------------------------------------------------------------
>
>



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Re: OSSIM as IDS

by Chris Griffin-8 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

OSSIM is just a front end for snort as the backend IDS.... im not sure
if it can also use prelude or not.

But OSSIM is not the "IDS" in itself. Just a single tool to manage
your IDS and nessus scans.

Unless things have changed.. its been a few years since I worked with it.



On Wed, May 21, 2008 at 12:21 PM,  <dkny@...> wrote:

> Good, but a lot of work to get it in place.
> David
>
> Quoting online_preeti@...:
>
>> Dear All,
>>
>> Is that anyone has worked on OSSIM as an open source for intrusion
>> detection?
>>
>> Regards
>> Preeti
>>
>> ------------------------------------------------------------------------
>> Test Your IDS
>>
>> Is your IDS deployed correctly?
>> Find out quickly and easily by testing it
>> with real-world attacks from CORE IMPACT.
>> Go to
>>  http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
>> to learn more.
>> ------------------------------------------------------------------------
>>
>>
>
>
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing itwith real-world attacks from CORE
> IMPACT.
> Go to
> http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfwto
> learn more.
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Re: OSSIM as IDS

by Tremaine Lea-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Unfortunately, that's true of most IDS worth the name.  Whether one is  
looking at Tipping Point, Sourcefire or another commercial offering,  
you're looking at a pretty good investment of time.


---
Tremaine Lea
Network Security Consultant
Intrepid ACL
"Paranoia for hire"



On 21-May-08, at 10:21 AM, dkny@... wrote:

> Good, but a lot of work to get it in place.
> David
>
> Quoting online_preeti@...:
>
>> Dear All,
>>
>> Is that anyone has worked on OSSIM as an open source for intrusion  
>> detection?
>>
>> Regards
>> Preeti
>>
>> ------------------------------------------------------------------------
>> Test Your IDS
>>
>> Is your IDS deployed correctly?
>> Find out quickly and easily by testing it
>> with real-world attacks from CORE IMPACT.
>> Go to  http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
>> to learn more.
>> ------------------------------------------------------------------------
>>
>>
>
>
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing itwith real-world attacks  
> from CORE IMPACT.
> Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfwto 
>  learn more.
> ------------------------------------------------------------------------
>


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Re: OSSIM as IDS

by Dogten :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Tremaine Lea wrote:

> Unfortunately, that's true of most IDS worth the name.  Whether one is
> looking at Tipping Point, Sourcefire or another commercial offering,
> you're looking at a pretty good investment of time.
>
>
> ---
> Tremaine Lea
> Network Security Consultant
> Intrepid ACL
> "Paranoia for hire"
>
>
>
> On 21-May-08, at 10:21 AM, dkny@... wrote:
>
>> Good, but a lot of work to get it in place.
>> David
>>
>> Quoting online_preeti@...:
>>
>>> Dear All,
>>>
>>> Is that anyone has worked on OSSIM as an open source for intrusion
>>> detection?
>>>
>>> Regards
>>> Preeti
We had a bad experience with OSSIM on high load networks, too many bells
and whistles. EasyIDS seems to be a better fit for us and comes with
wizard based configuration for Barnyard integration.

--
-dogten http://blog.memoryoffset.com

"I have not failed. I've just found 10,000 ways that won't work."
- Thomas Alva Edison (1847-1931)



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Parent Message unknown Re: Re: OSSIM as IDS

by preetichauhan1982 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Yes its a investment of time!
Hope its a fruitful.
well, I have installed the OSSIM server and able to login also but for generating reports some setting is to be made from front hand.
Is that anybody can help me in setting all that.

Preeti Chauhan
Security Analyst


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Re: Re: OSSIM as IDS

by Jakub-10 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

ossim's forums are great place to gain some knowledge,
i would suggest going there

also, dont take everything someone over internet tell you to do as
must_be_implemented

this is rather serious work

Jakub

2008/5/22  <preetichauhan1982@...>:

> Yes its a investment of time!
>
> Hope its a fruitful.
>
> well, I have installed the OSSIM server and able to login also but for generating reports some setting is to be made from front hand.
>
> Is that anybody can help me in setting all that.
>
>
> Preeti Chauhan
>
> Security Analyst
>
>
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
> to learn more.
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Parent Message unknown Re: Re: OSSIM as IDS

by nospam-14 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Well, two years ago you needed some skills to make it work. Perhaps you were not available to use the server correlation engine, perhaps you didn't write your own correlation rules, and perhaps you didn't write some plugins for all of this. You can make your own IDS rules, more sophisticated than with snort.

The agent has a easy and powerfull plugin system. So it's not just a frontend of snort. It started with snort as the main plugin but it can collect events from a lot of devices and logs.

Give it a try.

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------