936fc446c1
bsmtrace is a audit driven host based intrusion detection system which operates on finite state machine principles. Since it's audit driven, it requires that operating system security auditing be enabled. This requires FreeBSD 6.2 at a minimum. By default it provides real-time analysis through the use of an audit pipe, however it can operate on regular audit trail files as well. Approved by: Pav Reviewed by: Pav (and others)
6 lines
312 B
Text
6 lines
312 B
Text
bsmtrace is a BSM based intrusion detection system, utilizing audit trails
|
|
and real-time audit event analysis through auditpipe(4). This host based
|
|
IDS operates using a finite state machine principles with a flexible
|
|
sequence driven signature system.
|
|
|
|
WWW: http://people.freebsd.org/~csjp/bsmtrace/bsmtrace.txt
|