HIDS (Host Intrusion Detection system) is an application which is intended for monitoring and protecting the host computer system (server) and its network activities. This intrusion detection system is integrated into the server to detect the intruder attack activities and report the events to the network administrator. Throughout the years, different HIDS technology developed to counter, the computer crime with different type of attacks that attempts for entering the computer system. Therefore, the main goal of this paper is to provide a review of a most-widely used HIDS application called OSSEC. The evaluation process is conducted by applying some scenarios that practice the intruder activities who attempts to penetrate the host computer system. Each scenario is designed to run different intruder attacks that come from one or more attacker. Finally, the performance is evaluated by measuring the response time of OSSEC to detect the intrusion, the consumption of CPU and memory while detecting the intrusion.
Copyrights © 2020