Talk With an Expert

Using OSSEC with NETinVM

Using OSSEC with NETinVM (PDF, 2.98MB)Published: 17 Sep, 2010
Created by
Jon Mark Allen

We've long heard OSSEC was an excellent option for HIDS, but there is scarcity of detailed documentation on how to set up an OSSEC system. This paper will step through the installation, configuration, and use of OSSEC in a NETinVM environment. As a side effect, we will also see the benefits of having a NETinVM environment available for testing network attacks and defenses. We will very quickly review an OSSEC install (with some special considerations for the NETinVM environment), and jump right into developing an OSSEC policy. Once complete, we will develop a customized OSSEC configuration, based on our policy. To test our setup, we will launch an attack and see what OSSEC alerts are generated. Next, we will configure OSSEC to automatically respond to detected attacks and test the results.

Using OSSEC with NETinVM