PST2008
Sixth Annual Conference on
Privacy, Security and Trust
October 1-3, 2008, Delta Fredericton
Fredericton, New Brunswick, Canada
Tutorial #1
Open Source Host-based Intrusion Detection with OSSEC
Daniel B. Cid
Principal Researcher, OSSEC Development, Third Brigade
Description:
OSSEC is a multiplatform open source Host-Based IDS. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response. This tutorial will provide a technical overview of what OSSEC does, how it works, and how anyone can leverage it for their own internal security needs. We will also cover the concept of LIDS (log-based intrusion detection) and provide examples of how real attacks and policy violations were detected using it.
Technical Level: Intermediate
Bio:
Daniel B. Cid is the lead developer and founder of the OSSEC project. He has been working in the security area for many years, with a special interest in intrusion detection, log analysis and secure development. He is currently working at Third Brigade as a principal researcher. In the past, he worked at Q1 Labs, Sourcefire and NIH.
Daniel can be contacted at dcid@ossec.net