vonskippy wrote:
IDS is a COMPLETE waste of time.
It's like expecting a windscreen to collect space aliens, you'll spend all your time looking at smashed bugs and rarely if ever find an actual space alien (more likely, you'll just stop looking - after all one smashed bug looks pretty much like the other 57 bazallion that will show up).
Do you mean that the IDSes you have used have been too buggy to be useful? OSSEC is used on tens of thousands of systems daily and while there certainly are bugs, it's pretty stable. I personally know of environments running thousands of agents all reporting to one manager. And it does work.
vonskippy wrote:
Lurk thru a few of the Firewall App forums (Ipcop, PFsense, RouterOS, etc) and see what a major hoot-fest treatment IDS posts get.
Way better to setup a good edge firewall, watch it's logs, and setup good log filters on your APPS and see what shows up.
Firewall logs will not tell you about new users, changed files, rootkits, changed local ports, brute-force attempts against applications and a host of other things. Good luck watching firewall logs in real time. Can you read that fast? Or, you know, you could have OSSEC, which is capable of readings thousands of logs per second, watch for multiple dropped connections from the same IP and have it automatically shun the IP for 10 minutes. Or an hour. Or ten minutes the first time it sees the IP and an hour the next time. It's up to you.