| ARIS Sensor provides an easy way to get your Intrusion Detection System up and running on a newly installed Linux system. The ARIS Sensor RPM contains Snort 1.8.2, configured with a default ruleset, and ARIS extractor 1.6. This RPM is built on RedHat Linux 7.1. However, it should also correctly install on most other Linux systems. Both Snort and ARIS extractor are statically linked.
The SecurityFocus ARIS Extractor, included in this package, is a sophisticated IDS log analyzer, integrated with the SecurityFocus ARIS Analyzer web service. It parses your IDS logs (Snort, Cisco Secure IDS, Dragon, NetProwler, RealSecure, BlackICE defender, and ICEPac), converts them to a common (xml) format, strips IP addresses and other identifying information (configurable), and uploads it to ARIS Analyzer for detailed analysis. It lets you filter important attacks from the noise, allowing you to rapidly analyze IDS logs, report incidents, cross reference with vulnerability database information, generate personalized statistics and reports, etc. |