Host based
The purpose of a host-based intrusion detection system (HIDS) is to identify behavior on individual hosts which they are installed on. Behaviors typically monitored are attempts to identify unauthorized and anomalous behavior on that specific host. A HIDS typically installed an agent that is used to monitor each system and alerts on local OS and application activity. The locally-installed agent uses a combination or algorithm that uses signatures, rules, and heuristics to identify unauthorized or unusual activity. Keep in mind that a HIDS is an IDS and its role is only passive; meaning that it is only gathering, identifying, logging, and alerting. An example of a HIDS would be Tripwire and open source host-based intrusion detection ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access