- Instant OSSEC Host-based Intrusion Detection System
- Brad Lhotsky
- 269字
- 2021-08-13 16:28:00
Getting ready
So, what is it we're getting ourselves into? OSSEC is an acronym for Open Source SECurity Event Correlator. OSSEC monitors systems for events in logfiles and processes on the filesystem through the use of commands and outputs. It decodes the data, extracting valuable information, and analyzes it in context.

As the previous diagram shows, the analysis and correlation is used to generate alerts, either e-mails or logs, or active responses. Active response is a simple framework for running a script or program within the context of the alert. Using active response, we can call a firewall script with the source IP that just failed to log in to our server via SSH.
The functionality of the local profile is identical to that of the server-agent model, except all components function locally. Let's start out with a simple local profile installation.
To install OSSEC from source, you will need only a C compiler available on the system and the superuser access. OSSEC does not require any external libraries and builds its own self-contained binaries to avoid corruption or deception should your server be compromised.
Generally, most Linux/BSD operating systems ship with or have a C compiler available. It's usually the GNU C compiler (GCC). If GCC isn't already installed, you can simply consult your system's package manager to install it on any Linux- or BSD-based systems.
Now the only thing left to prepare is downloading and extracting the source tarball. You can retrieve the proper archive file from http://www.ossec.net/?page_id=19. Download the latest stable release, extract it, and change its directory into the folder created for extracting the archive.
- 云原生安全:攻防實踐與體系構(gòu)建
- 信息安全導(dǎo)論(在線實驗+在線自測)
- 網(wǎng)絡(luò)安全應(yīng)急管理與技術(shù)實踐
- Preventing Digital Extortion
- 云原生安全技術(shù)實踐指南
- API安全技術(shù)與實戰(zhàn)
- 軟件安全保障體系架構(gòu)
- 情報驅(qū)動應(yīng)急響應(yīng)
- 信息安全等級保護測評與整改指導(dǎo)手冊
- 電腦安全與攻防入門很輕松(實戰(zhàn)超值版)
- 構(gòu)建新型網(wǎng)絡(luò)形態(tài)下的網(wǎng)絡(luò)空間安全體系
- 云計算安全防護技術(shù)
- INSTANT Kali Linux
- 網(wǎng)絡(luò)空間安全法律問題研究
- Kali Linux無線網(wǎng)絡(luò)滲透測試詳解