OSSIM

Submitted by doug on Thu, 2007-10-18 19:11.Availability

Open Source Security Information Management

www.ossim.com/

Sun, 2002-04-14 19:00

security information management open source intrusion detection vulnerability scanning information monitoring

Active

OSSIM stands for Open Source Security Information Management and compiles more than 15 open source security programs providing all the technology levels to cover the full Security Management cycle.

The OSSIM Sensors integrate powerful open source technology for:

Attack Detection using Snort IDS for real time detection
Vulnerability Scanning using Nessus Vulnerability Scanner
Network Monitoring and Profiling thanks to Ntop
Anomaly Detection with spade, RRD aberrant-behaviour, arpwatch, pads and p0f

Analyzing the local situation up to the deepest details as for example:

  • Detecting Attacks, Virus or Trojan Patterns
  • Locating active Vulnerabilities
  • Detecting Abnormal Beaviour of malicious internal users
  • Detecting unknown Viruses and Worms Activity
  • Giving an up-to-the-packet detail snapshot of the traffic
  • Creating detailed Profiles of Network and Hosts traffic usage and detecting Anomalies
  • Feeding the Automatic Inventory

Trackback URL for this post:

http://lopsa.org/trackback/1530