Serious Discussion FOSS IDS/IPS for home use for a power user?

General Security Discussions
7 Replies 874 Views
If you have an old pc, you can add a $10 network card (total of 2 nic's), and install the pfSense firewall. Then install the included add-on snort IPS. Then subscribe to the free snort community rules and free emergingThreats rules.

There you have it, free hardware firewall.
 
If you have an old pc, you can add a $10 network card (total of 2 nic's), and install the pfSense firewall. Then install the included add-on snort IPS. Then subscribe to the free snort community rules and free emergingThreats rules.

There you have it, free hardware firewall.
I've read IDS/IPS is useless because nowadays all malware/hacker traffic is encrypted anyways. Is this true?
 
But the initial exploit won't be encrypted. The encryption will be used after the exploit when the adversary sets up his C2. That is if they are not attacking the browser, which uses https.

You asked for an IPS, so I gave you one.

There is another one called OPNSense, but I am not familiar with that one.
 
Last edited:
I've read IDS/IPS is useless because nowadays all malware/hacker traffic is encrypted anyways. Is this true?
There is a thing called SSL Decryptor. This decrypt and reencrypt traffic after inspection for IDPS purposes.

Cisco Firepower are made from SourceFire which is using Snort IPS/IDS with ClamAV and are using the Technology called Firepower SSL Decryption.
IDS/IPS is not dead. It's mostly deployed at the gateway in the network and endpoint users don't really notice it.
 
I've read IDS/IPS is useless because nowadays all malware/hacker traffic is encrypted anyways. Is this true?
The claim that Intrusion Detection/Prevention Systems (IDS/IPS) are useless because all modern traffic is encrypted is a significant oversimplification. While it's true that widespread encryption, such as TLS/SSL, creates a "blind spot" for traditional systems, it hasn't rendered them obsolete. These systems have evolved and remain a crucial part of a robust cybersecurity strategy. Modern IDS/IPS can still analyze unencrypted metadata to identify threats. For instance, they inspect source and destination IP addresses and ports, which allows them to block traffic to known malicious IPs. They also monitor traffic volume and timing, with unusual spikes or communication patterns often serving as red flags. Additionally, by analyzing TCP/IP header information, they can detect low-level network attacks like port scans and SYN floods. Furthermore, these systems have adapted in other ways, including the use of behavioral analysis and machine learning to identify anomalous traffic patterns even when payloads are encrypted. Some organizations even deploy SSL/TLS inspection, where the IDS/IPS decrypts, inspects, and then re-encrypts the traffic to gain full visibility. Finally, host-based IDS/IPS (HIDS/HIPS) systems are installed directly on endpoints, giving them a clear view of data before and after encryption, thereby bypassing the network encryption problem entirely. In short, while encrypted traffic presents a challenge, IDS/IPS have adapted and continue to be an effective layer in a comprehensive "defense-in-depth" security model.
 
Or you can try Xcitium - Comodo's EDR arm, the actively developed version of their famous Comodo Internet Security + a web based alerts console + optional central control of all pc's. $8/month/pc postpaid. It has a HIPS. You can learn a lot about your pc by watching the alerts.

Unlike many EDR vendors, Xcitium does not have a minimum # of pc's requirement.
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top