From owner-freebsd-questions@FreeBSD.ORG Mon Apr 18 12:47:09 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D831916A4CE for ; Mon, 18 Apr 2005 12:47:09 +0000 (GMT) Received: from zproxy.gmail.com (zproxy.gmail.com [64.233.162.206]) by mx1.FreeBSD.org (Postfix) with ESMTP id 79E3D43D5A for ; Mon, 18 Apr 2005 12:47:09 +0000 (GMT) (envelope-from bjmccann@gmail.com) Received: by zproxy.gmail.com with SMTP id 16so374958nzp for ; Mon, 18 Apr 2005 05:47:08 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=C66h6y8v3W1daszExkvwfCYWjBdY3sAg+/6jArRLWWQgnISW1qxAOMdqrCtAJr1g+BTT7nA/i+LYYsWDQFFnchrVutk/Pjgu8UnQokRpoJzsrubmnVKAqlDrS8gi+177jqNrWfTxJTA2fuA2fCg1WSWiMESOufJQLGJ/smVxeH4= Received: by 10.36.89.13 with SMTP id m13mr369219nzb; Mon, 18 Apr 2005 05:47:08 -0700 (PDT) Received: by 10.36.47.11 with HTTP; Mon, 18 Apr 2005 05:47:08 -0700 (PDT) Message-ID: <2b5f066d05041805476800a853@mail.gmail.com> Date: Mon, 18 Apr 2005 08:47:08 -0400 From: Brian McCann To: FreeBSD questions Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Subject: IDS Recomendations X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Brian McCann List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Apr 2005 12:47:10 -0000 This should probably be posted to freebsd-security, but I figured I'd start here first. I've got to start to implement an IDS system, and I'm wondering what any of you guys are using for software. I've always used Snort & ACID, but I'm curious how others feel. I've seen Prelude, and it looks kinda cool, but Snort & ACID have proved themselves over many years. Any thoughts or suggestions? --Brian _-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_-=3D-_ Brian McCann Systems & Network Administrator, K12USA "I don't have to take this abuse from you -- I've got hundreds of people waiting to abuse me." -- Bill Murray, "Ghostbusters"