content:en_us:7_ug_intrusion_detection

Intrusion Detection

The Intrusion Detection app is included with ClearOS to make users more aware of some of the daily hostile traffic that can pass by your Internet connection. The software is able to detect and report unusual network traffic including attempted break-ins, trojans/viruses on your network, and port scans.

Installation

If your system does not have this app available, you can install it via the Marketplace.

You can find this feature in the menu system at the following location:

<navigation>Gateway|Intrusion Protection|Intrusion Detection</navigation>

Configuration

The Basic ClearOS installation only includes rules published under the GPL licence and is relatively old and limited. You can select the rule sets from the default rules you would like to enable. If you would like more up-to-date rules please see the Intrusion Protection Updates below.

There is no point enabling rules for services which are not exposed to the internet. E.g if you only use IMAP for picking up e-mails, there is no point in enabling the POP3 rules

Intrusion Protection Updates and ClearCenter

The ClearCenter IDS Signatures update service is strongly recommended for deploying an effective intrusion protection system. These signatures are compiled from third party organizations as well as internal engineering resources from ClearCenter. We keep tabs on the latest available updates and fine tune the system so you can focus on more important things.

The IDS Signatures app:

  • Provides 13,000+ additional signatures (compared to the base 1,150 signatures)
  • Weekly updates to keep up with the latest threats
content/en_us/7_ug_intrusion_detection.txt · Last modified: 2018/04/30 14:09 by nickh