IDS.
IDS, - (, Kerio WinRoute Firewall Microsoft ISA Server). IDS - , , ). .
IDS ( ) - SNORT (www.snort.org). Unix, Windows. , SNORT Windows - IDSCenter. SNORT, Windows , EagleX ( IDS -). SNORT , , ( ). - , , , (Apache, Perl, mySQL ..). SNORT - . , , Web- Apache DNS- BIND.
( , , , ). McAfee Entercept ETrust Intrusion Detection Computer Associates.
, . . Internet Periscope. , IP-, , ..
IDS , , Windows ( ). , , GFI SELM.
, ( ). CheckPoint NetScreen.
IDS
IDS (HIDS) , . , (, , ). HIDS . HIDS . , , . HIDS , .[49]
|
|
HIDS, ( ), , , , . .
HIDS, , . , Windows HIDS , , , , , . Unix HIDS , /etc/passwd, setuid setgid, ( . Unix, , crontab). HIDS, -, HTML-, SQL.
HIDS, . HIDS , . , , , , - . , , , . , , , HIDS HIDS, .
HIDS, , . . HIDS . . , . , HIDS , HIDS, , . , , , . , .
|
|
. . , , . , , . , , . HIDS, , , . , .
HIDS honeypot
. HIDS - . Honeypot HIDS, , . , , - ; , honeypot. honeypot , IP- , , , .
honeypot , , -. LaBrea honeypot, , IP- . , .. - .[50]
IDS (NIDS)
IDS (NIDS) , , . HIDS, NIDS . , , . , ; . .
HIDS , , . NIDS , , NIDS- , . , NIDS , IDS . - , , - , NIDS , . NIDS , NIDS. NIDS . NIDS , , , NIDS. NIDS .
|
|
. , . Unix Windows , IDS- , libpcap WinPcap 3.0. , tcpdump (www.tcpdump.org) WinDump (http://windump.poIito.it), IDS, . IDS .
. NIDS , . , .. , . , unicast-, , broadcast-, , , multicast-, . unicast- broadcast-. Multicast- , , -, . , , , (, ..). IDS , , .[51]
. NIDS , , , .
, NIDS- . IDS , . - , NIDS . , . , , IDS. IDS. , , IP -, . Intrusion Inc. (www.intrusion.com) .
|
|
, , . . - , , , . , , .
Ethernet- . , . IDS , , .
. -, IDS . , . -, ( ). , IDS.
-, , . , . , , , . .
, . .
-, , , . , . , IDS ARP -, . , .
IDS Ethernet , . , , IDS- , .[52]