Caramel2

Junior Member
Jun 1, 2012
1
0
0
Hi,

I am looking for a good Host-based IDS solution for Linux (one that inspects system calls, OS files, CPU usage etc.,,, network traffic inspection is not relevant for this case).

Since I am using it for research purposes I need it to give as an output not only alerts, but also some quantitative measure of the risk to the system (such as anomaly rate) .

Does anyone have an idea of an existing IDS (Maybe OSSEC will do the job)?

If not - do you have an idea how to build such an HIDS?

Thanks
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
OSSEC doesn't inspect system calls or really look at CPU usage. "Quantitative measure of risk to the system" is up to the user to figure out (along with delicious fat free bacon).