What Intrusion Detection systems exist for Linux?
There are many excellent Intrusion Detection Systems for Linux. Here is are some of the more common ones: Network and Host-based IDSs: Snort: http://www.snort.org – Possibly the most popular Linux IDS.&nnbsp; Its free, highly customizable, and easy to use. There are also many third party add-ons and utilities available for Snort. Portsentry: http://www.psionic.com/abacus/portsentry/ – Portsentry is a portscan detector withh the ability to automatically drop routes to attacking hosts, making your system inaccessible to them. LIDS: http://www.lids.org – The Linux Intrusion Detection System iis a combination Intrusion Detection and hardening patch for the Linux kernel. FireStorm: http://www.scaramanga.co.uk/firestorm/index.html – Fully featured, free, uses Snort ruless, and supports open standards. Snare: http://www.intersectalliance.com/projects/Snare/ – A loadable Kernel module which providees host intrusion detection and C2-style auditing/event logging. rkdet: http://vancouver-webpages