Nutter helps a user who needs an IDS on the cheap.
I just started at a company where there had been a problem in the past with the firewall being hacked/bypassed by hackers. The problem was fixed, but I can’t convince management to spend some money to put a better system in place or to help identify when someone is attempting to hack us. Any suggestions?
— Via the Internet
Depending on your current firewall configuration, there may be an option at the right price that should help prove to management that you need better resources. Most firewalls have support for reporting to a syslog console a problem or condition that needs to be looked at. Syslog (RFC 3164) provides for a mechanism that gets you access to information that may not be available from a vendor’s device any other way. You have several ways of setting up this type of console and it may not require a Unix/Linux system to do it. One Windows-based options is called Kiwi Syslog. There are two versions of this program. The basic one will get you up and running. The registered version allows you to send the information to an Access or SQL database for more extensive data analysis.
How good the information you get is based solely on how much information the device you have reporting to syslog has been configured to create. Some devices, such as MultiTech’s SOHO VPN router, will give you messages indicating the source IP, port number, and destination IP and port number that are involved in what appears to be a possible hacking situation. Some devices only report via SNMP, but Kiwi Syslog’s product is still an option – just make sure your SNMP community names match. If you find that your current firewall doesn’t support syslog or has limited SNMP reporting functionality, consider getting the MultiTech SOHO router (less than $200) or a similar device and put this outside the firewall as a “target” for hackers to go after.
While not a true intrusion-detection system by some standards, it at least will give you an option of seeing when potential problems exist. It can also help give you a log that can be used to report the problem to the abuse groups that exist at most major ISPs or to report the problem to services such as Dshield.org where you can share information with other Internet users. This at least is an option you can start with until you can find something that may be better suited to what you want to do.




