<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure2S &#187; Intrusion Detection Systems</title>
	<atom:link href="http://secure2s.net/en/category/tools/ids/feed/" rel="self" type="application/rss+xml" />
	<link>http://secure2s.net/en</link>
	<description>Security Tools</description>
	<lastBuildDate>Sat, 10 Jul 2010 13:44:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Sguil</title>
		<link>http://secure2s.net/en/tools/ids/sguil/201/</link>
		<comments>http://secure2s.net/en/tools/ids/sguil/201/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 12:38:28 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=201</guid>
		<description><![CDATA[Sguil : The Analyst Console for Network Security Monitoring Sguil (pronounced sgweel) is built by network security analysts for network security analysts. Sguil&#8217;s main component is an intuitive GUI that provides realtime events from Snort/barnyard. It also includes other components which facilitate the practice of Network Security Monitoring and event driven analysis of IDS alerts. <a href='http://secure2s.net/en/tools/ids/sguil/201/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/snort/8/' rel='bookmark' title='Permanent Link: Snort'>Snort</a></li>
<li><a href='http://secure2s.net/en/tools/ids/base/194/' rel='bookmark' title='Permanent Link: BASE'>BASE</a></li>
<li><a href='http://secure2s.net/en/tools/traffic-monitoring/nagios/162/' rel='bookmark' title='Permanent Link: Nagios'>Nagios</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fsguil%2F201%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fsguil%2F201%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://sguil.sourceforge.net/">Sguil</a> : The Analyst Console for Network Security Monitoring<br />
Sguil (pronounced sgweel) is built by network security analysts for network security analysts. Sguil&#8217;s main component is an intuitive GUI that provides realtime events from <a href="http://sectools.org/index.html#snort">Snort</a>/barnyard. It also includes other components which facilitate the practice of Network Security Monitoring and event driven analysis of IDS alerts.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=201&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/snort/8/' rel='bookmark' title='Permanent Link: Snort'>Snort</a></li>
<li><a href='http://secure2s.net/en/tools/ids/base/194/' rel='bookmark' title='Permanent Link: BASE'>BASE</a></li>
<li><a href='http://secure2s.net/en/tools/traffic-monitoring/nagios/162/' rel='bookmark' title='Permanent Link: Nagios'>Nagios</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/ids/sguil/201/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BASE</title>
		<link>http://secure2s.net/en/tools/ids/base/194/</link>
		<comments>http://secure2s.net/en/tools/ids/base/194/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 12:36:34 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=194</guid>
		<description><![CDATA[BASE : The Basic Analysis and Security Engine BASE is a PHP-based analysis engine to search and process a database of security events generated by various IDSs, firewalls, and network monitoring tools. Its features include a query-builder and search interface for finding alerts matching different patterns, a packet viewer/decoder, and charts and statistics based on <a href='http://secure2s.net/en/tools/ids/base/194/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/snort/8/' rel='bookmark' title='Permanent Link: Snort'>Snort</a></li>
<li><a href='http://secure2s.net/en/tools/information-gathering/seat/318/' rel='bookmark' title='Permanent Link: SEAT'>SEAT</a></li>
<li><a href='http://secure2s.net/en/tools/ids/ossec-hids/139/' rel='bookmark' title='Permanent Link: OSSEC HIDS'>OSSEC HIDS</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fbase%2F194%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fbase%2F194%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://sourceforge.net/projects/secureideas/">BASE</a> : The Basic Analysis and Security Engine<br />
BASE is a PHP-based analysis engine to search and process a database of security events generated by various IDSs, firewalls, and network monitoring tools. Its features include a query-builder and search interface for finding alerts matching different patterns, a packet viewer/decoder, and charts and statistics based on time, sensor, signature, protocol, IP address, etc.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=194&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/snort/8/' rel='bookmark' title='Permanent Link: Snort'>Snort</a></li>
<li><a href='http://secure2s.net/en/tools/information-gathering/seat/318/' rel='bookmark' title='Permanent Link: SEAT'>SEAT</a></li>
<li><a href='http://secure2s.net/en/tools/ids/ossec-hids/139/' rel='bookmark' title='Permanent Link: OSSEC HIDS'>OSSEC HIDS</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/ids/base/194/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fragroute_Fragrouter</title>
		<link>http://secure2s.net/en/tools/ids/fragroute_fragrouter/164/</link>
		<comments>http://secure2s.net/en/tools/ids/fragroute_fragrouter/164/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:42:01 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=164</guid>
		<description><![CDATA[Fragroute/Fragrouter : A network intrusion detection evasion toolkit Fragrouter is a one-way fragmenting router &#8211; IP packets get sent from the attacker to the Fragrouter, which transforms them into a fragmented data stream to forward to the victim. Many network IDS are unable or simply don&#8217;t bother to reconstruct a coherent view of the network <a href='http://secure2s.net/en/tools/ids/fragroute_fragrouter/164/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/packet-sniffers/dsniff/45/' rel='bookmark' title='Permanent Link: Dsniff'>Dsniff</a></li>
<li><a href='http://secure2s.net/en/tools/traffic-monitoring/argus/249/' rel='bookmark' title='Permanent Link: Argus'>Argus</a></li>
<li><a href='http://secure2s.net/en/tools/ids/ossec-hids/139/' rel='bookmark' title='Permanent Link: OSSEC HIDS'>OSSEC HIDS</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Ffragroute_fragrouter%2F164%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Ffragroute_fragrouter%2F164%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.monkey.org/%7Edugsong/fragroute/">Fragroute</a>/<a href="http://www.packetstormsecurity.nl/UNIX/IDS/nidsbench/fragrouter.html">Fragrouter</a> : A network intrusion detection evasion toolkit<br />
Fragrouter is a one-way fragmenting router &#8211; IP packets get sent from the attacker to the Fragrouter, which transforms them into a fragmented data stream to forward to the victim. Many network IDS are unable or simply don&#8217;t bother to reconstruct a coherent view of the network data (via IP fragmentation and TCP stream reassembly), as discussed in <a href="http://insecure.org/stf/secnet_ids/secnet_ids.html">this classic paper</a>. Fragrouter helps an attacker launch IP-based attacks while avoiding detection.  It is part of the <a href="http://www.packetstormsecurity.nl/UNIX/IDS/nidsbench/nidsbench.html">NIDSbench</a> suite of tools by Dug Song.  Fragroute is a similar tool which is also by Dug Song.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=164&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/packet-sniffers/dsniff/45/' rel='bookmark' title='Permanent Link: Dsniff'>Dsniff</a></li>
<li><a href='http://secure2s.net/en/tools/traffic-monitoring/argus/249/' rel='bookmark' title='Permanent Link: Argus'>Argus</a></li>
<li><a href='http://secure2s.net/en/tools/ids/ossec-hids/139/' rel='bookmark' title='Permanent Link: OSSEC HIDS'>OSSEC HIDS</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/ids/fragroute_fragrouter/164/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSSEC HIDS</title>
		<link>http://secure2s.net/en/tools/ids/ossec-hids/139/</link>
		<comments>http://secure2s.net/en/tools/ids/ossec-hids/139/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:31:52 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=139</guid>
		<description><![CDATA[OSSEC HIDS : An Open Source Host-based Intrusion Detection System OSSEC HIDS performs log analysis, integrity checking, rootkit detection, time-based alerting and active response. In addition to its IDS functionality, it is commonly used as a SEM/SIM solution. Because of its powerful log analysis engine, ISPs, universities and data centers are running OSSEC HIDS to <a href='http://secure2s.net/en/tools/ids/ossec-hids/139/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/base/194/' rel='bookmark' title='Permanent Link: BASE'>BASE</a></li>
<li><a href='http://secure2s.net/en/tools/ids/snort/8/' rel='bookmark' title='Permanent Link: Snort'>Snort</a></li>
<li><a href='http://secure2s.net/en/tools/ids/fragroute_fragrouter/164/' rel='bookmark' title='Permanent Link: Fragroute_Fragrouter'>Fragroute_Fragrouter</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fossec-hids%2F139%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fossec-hids%2F139%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.ossec.net/">OSSEC HIDS</a> : An Open Source Host-based Intrusion Detection System<br />
OSSEC HIDS performs log analysis, integrity checking, rootkit detection, time-based alerting and active response. In addition to its IDS functionality, it is commonly used as a SEM/SIM solution. Because of its powerful log analysis engine, ISPs, universities and data centers are running OSSEC HIDS to monitor and analyze their firewalls, IDSs, web servers and authentication logs.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=139&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/base/194/' rel='bookmark' title='Permanent Link: BASE'>BASE</a></li>
<li><a href='http://secure2s.net/en/tools/ids/snort/8/' rel='bookmark' title='Permanent Link: Snort'>Snort</a></li>
<li><a href='http://secure2s.net/en/tools/ids/fragroute_fragrouter/164/' rel='bookmark' title='Permanent Link: Fragroute_Fragrouter'>Fragroute_Fragrouter</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/ids/ossec-hids/139/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Snort</title>
		<link>http://secure2s.net/en/tools/ids/snort/8/</link>
		<comments>http://secure2s.net/en/tools/ids/snort/8/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 19:05:01 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=8</guid>
		<description><![CDATA[Snort : Everyone&#8217;s favorite open source IDS This lightweight network intrusion detection and prevention system excels at traffic analysis and packet logging on IP networks. Through protocol analysis, content searching, and various pre-processors, Snort detects thousands of worms, vulnerability exploit attempts, port scans, and other suspicious behavior. Snort uses a flexible rule-based language to describe <a href='http://secure2s.net/en/tools/ids/snort/8/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/base/194/' rel='bookmark' title='Permanent Link: BASE'>BASE</a></li>
<li><a href='http://secure2s.net/en/tools/ids/ossec-hids/139/' rel='bookmark' title='Permanent Link: OSSEC HIDS'>OSSEC HIDS</a></li>
<li><a href='http://secure2s.net/en/tools/ids/sguil/201/' rel='bookmark' title='Permanent Link: Sguil'>Sguil</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fsnort%2F8%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Fids%2Fsnort%2F8%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.snort.org/">Snort</a> : Everyone&#8217;s favorite open source IDS<br />
This lightweight network intrusion detection and prevention system excels at traffic analysis and packet logging on IP networks. Through protocol analysis, content searching, and various pre-processors, Snort detects thousands of worms, vulnerability exploit attempts, port scans, and other suspicious behavior. Snort uses a flexible rule-based language to describe traffic that it should collect or pass, and a modular detection engine. Also check out the free <a href="http://secureideas.sourceforge.net/">Basic Analysis and Security Engine (BASE)</a>, a web interface for analyzing Snort alerts.</p>
<p>Open source Snort works fine for many individuals, small businesses, and departments.  Parent company <a href="http://www.sourcefire.com/">SourceFire</a> offers a complimentary product line with more enterprise-level features and real-time rule updates. They offer a free (with registration) 5-day-delayed rules feed, and you can also find many great free rules at <a href="http://www.bleedingsnort.com/">Bleeding Edge Snort</a>.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=8&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/ids/base/194/' rel='bookmark' title='Permanent Link: BASE'>BASE</a></li>
<li><a href='http://secure2s.net/en/tools/ids/ossec-hids/139/' rel='bookmark' title='Permanent Link: OSSEC HIDS'>OSSEC HIDS</a></li>
<li><a href='http://secure2s.net/en/tools/ids/sguil/201/' rel='bookmark' title='Permanent Link: Sguil'>Sguil</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/ids/snort/8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
