<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Administrators &#187; centralized policy</title>
	<atom:link href="http://itadmins.org/tag/centralized-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://itadmins.org</link>
	<description>The Techs that Drive Tech</description>
	<lastBuildDate>Sat, 27 Aug 2011 17:18:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>I&#8217;ve finally found a decent IDS</title>
		<link>http://itadmins.org/os/ive-finally-found-a-decent-ids/</link>
		<comments>http://itadmins.org/os/ive-finally-found-a-decent-ids/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 02:30:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[added benefit]]></category>
		<category><![CDATA[based intrusion detection]]></category>
		<category><![CDATA[centralized configuration]]></category>
		<category><![CDATA[centralized policy]]></category>
		<category><![CDATA[config]]></category>
		<category><![CDATA[correlation]]></category>
		<category><![CDATA[cross platform]]></category>
		<category><![CDATA[existing records]]></category>
		<category><![CDATA[fessenden]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[linux link]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[operating systems]]></category>
		<category><![CDATA[ossec]]></category>
		<category><![CDATA[platforms]]></category>
		<category><![CDATA[solaris]]></category>
		<category><![CDATA[source host]]></category>
		<category><![CDATA[windows registry]]></category>

		<guid isPermaLink="false">http://itadmins.org/?p=58</guid>
		<description><![CDATA[Linc Fessenden from the Linux Link Tech Show mentioned OSSEC a few weeks ago and recommended everyone check it out. According to the project&#8217;s about page: OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection System (HIDS). It has a powerful correlation and analysis engine, integrating log analysis, file integrity checking, Windows registry monitoring, [...]]]></description>
			<content:encoded><![CDATA[<p id="top" /><a href="http://ossec.net/"><img style="vertical-align: top;" src="Http://itadmins.org/images/ossec_logo.jpg" alt="OSSEC Logo" width="191" height="81" align="top" /></a></p>
<p><a href="http://lincgeek.org/">Linc Fessenden</a> from the <a href="http://www.tllts.org">Linux Link Tech Show</a> mentioned OSSEC a few weeks ago and recommended everyone check it out.  According to the project&#8217;s about page:</p>
<blockquote><p>OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection System (HIDS). It has a powerful correlation and analysis engine, integrating log analysis, file integrity checking, Windows registry monitoring, centralized policy enforcement, rootkit detection, real-time alerting and active response.</p>
<p>It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS, Solaris and Windows. A list with all supported platforms is available <a href="http://www.ossec.net/wiki/index.php/Supported_Systems">here</a>.</p></blockquote>
<p>After testing it out on several of my machines, I can officially say it&#8217;s exactly what I was looking for in an IDS: something lightweight, cross-platform, and well documented.  My setup involved installing it as a local instance on every machine, rather than the centralized config.  Viewing the logs for every machine in one place doesn&#8217;t really appeal to me.  I just need something that will nag me and say, &#8220;Hey, Dummy!  You misconfigured that install you attempted at 3am.  Fix it!&#8221;  The added benefit of receiving the alerts offsite is that the existing records are stored in my Gmail.  Even if someone did manage to root a computer, the logs wouldn&#8217;t be on the box and the creator of the kit wouldn&#8217;t be able to bury his/her tracks.</p>
<p>My hope is to test the centralized configuration in the future, but for the moment there is no benefit.</p>
<p>This is absolutely what I was looking for in intrusion detection.  Go check OSSEC out when you get a chance.</p>
]]></content:encoded>
			<wfw:commentRss>http://itadmins.org/os/ive-finally-found-a-decent-ids/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

