Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Cloudasware Cloudaware IDS is a full platform to monitor and control systems. It mixes together all the aspects of HIDS (host-based intrusion detection), log monitoring and SIM/SIEM together in a simple, powerful solution.

...

HIDS Server Deployment Options


CloudAware HIDS Cloudaware HIDS solution consists of three parts:

...

Agents are deployed onto every host where Intrusion Detection capabilities are desired. IDS Servers are managed by CloudAware by Cloudaware if a customer is using Managed IDS option.

Optionally, customers can deploy their own IDS servers. IDS dashboard is part of the CloudAware the Cloudaware and all IDS servers report into the dashboard. There are two ways to deploy CloudAware deploy Cloudaware IDS services.


Managed IDS


Using Managed IDS deployment option, customers leverage IDS servers that are managed by CloudAwareCloudaware.

    

Advantages

Disadvantages

  • Hassle free operations
  • Customers do not need to worry about IDS Server's 
    • availability
    • patching
    • performance
    • costs
    • scalability
    • maintenance
Not able to deploy common OSSEC customizations without involving CloudAware involving Cloudaware support.


Customer Managed IDS

...

Under this approach customers maintain their own set of IDS servers and are responsible for many operational aspects including backup, disaster recovery and availability. CloudAware  Cloudaware recommends one IDS server per 500 agents and that IDS servers are deployed in the same region as agents. 


Customers may also choose to deploy a hybrid approach where some agents use CloudAwareCloudaware-managed IDS servers and some agents user customer-managed IDS servers. 


Wazuh


Wazuh, a Host-based Intrusion Detection service provided by Cloudaware via Kibana platform user interface. You can access Wazuh application from Cloudaware Launcher.


You can use Raw Data UI to query & filter your data and/or create Dashboards to review the summary of alerts on an instance level, monitor status of agents and build any vizualizations that are meaningful to you:


Image Modified    Image Modified


IDS Status in CMDB


If Intrusion Detection module is enabled, check an instance in Cloudaware CMDB. The tile 'IDS' may display 3 values:

  • Monitored
  • Not monitored
  • Under Attack



Click the tab 'Security' to review HIDS Alerts:

...