Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Cloudaware IDS is a full platform to monitor and control systems. It mixes together all the aspects of HIDS (host-based intrusion detection), log monitoring and SIM/SIEM together in a simple, powerful solution.

...

Cloudaware IDS lets customers implement a comprehensive host based intrusion detection system with fine grained application/server specific policies across multiple platforms such as Linux, Solaris, AIX, HP-UX, BSD, Windows, Mac and Vmware VMWare ESX.

Real-time and Configurable Alerts

Cloudaware IDS lets customers configure incidents they want to be alerted on which lets them focus on raising the priority of critical incidents over the regular noise on any system. Integration with smtpSMTP, sms SMS and syslog Syslog allows customers to be on top of alerts by sending these on to e-mail and handheld devices such as cell phones and pagers. Active response options to block an attack immediately is also available.

...

Cloudaware IDS provides a simplified centralized management server to manage policies across multiple operating systems. Additionally, it also lets customers define server specific overrides for finer-grained policies.

Agent and Agentless Monitoring

...

Using Managed IDS deployment option, customers leverage IDS servers that are managed by Cloudaware.

 

Advantages

Disadvantages

  • Hassle free operations

  • Customers do not need to worry about IDS Server's 

    • availability

    • patching

    • performance

    • costs

    • scalability

    • maintenance

Not able to deploy common OSSEC customizations without involving Cloudaware support.

Customer Managed IDS

Under this approach customers maintain their own set of IDS servers and are responsible for many operational aspects including backup, disaster recovery and availability. Cloudaware recommends one IDS server per 500 agents and that IDS servers are deployed in the same region as agents. 
Customers may also choose to deploy a hybrid approach where some agents use Cloudaware-managed IDS servers and some agents user customer-managed IDS servers. 

Wazuh

Wazuh , is a Host-based Intrusion Detection service provided by Cloudaware via Kibana platform user interface. You can access Wazuh application from Cloudaware Launcher.

You can use Raw Data UI to query & filter your data and/or create Dashboards to review the summary of alerts on an instance level, monitor status of agents and build any vizualizations that are meaningful to you:

    

IDS Status in CMDB

If Intrusion Detection module is enabled, check an instance in Cloudaware CMDB. The tile 'IDS' may display 3 values:

  • Monitored

  • Not monitored

  • Under Attack

...

Click the tab 'Security' to review HIDS Alerts:

...