
125Intrusion Detection Systems for Critical Infrastructure
analyze their rewalls, IDSs, web servers, and authentication logs. OSSEC also can be categorized
as a log-based IDS (LIDS) as it uses logs as the primary source for detection.
A HIDS detects attacks against a specic host by analyzing audit data produced by the host operating
systems. OSSEC HIDS are widely available to provide intrusion detection for most operating systems,
including Windows, Linux, Solaris, AIX, HP-UX, OpenBSD, FreeBSD, Mac OS X, and VMWare ESX.
As OSSEC implements a centralized, cross-platform architecture, it is relatively easy to monitor
and manage multiple systems ...