Georgian Scientists/ . 6 N 3, 2024 1 Georgian Scientists Vol. 6 Issue 3, 2024 https://doi.org/10.52340/gs.2024.06.03.01 1, 2, . 3, . 4, 5 , , s.qarTvelishvili@gtu.ge, ORCID: 0000-0001-9890- 4099; 2 , , m.okhanashvili@gtu.ge, , , i.abuladze@gtu.ge, 4 , , n.chorkhauli@gtu.ge; , , misha8003123@gmail.com . , , , , . (Cisco, Snort, ISS RealSecure, .) . . . , . , . IDS (Intrusion Detection System)- . : . , Georgian Scientists/ . 6 N 3, 2024 2 . ( ISS RealSecure, Symantec Network Security, Cisco IPS .) . , . , , , . IDS - , , ( ) , . , , . , - , , . IDS : - IDS ( (Network-based) IDS, NIDS); - IDS ( (Host-based) IDS, HIDS); - IDS ( (Hybrid) IDS). IDS- : IDS IDS ( (application-based) IDS). : Snort. Bro. STAT. Prelude. OSSEC. Cisco Secure IPS. RealSecure (IBM ISS). Symantec Network Security. eTrust Intrusion Detection Computer Associates. Snort Snort . , , , , , CGI , . Snort . 3 : sniffer, packet logger network intrusion detection system. Georgian Scientists/ . 6 N 3, 2024 3 , , , . .1 . , , (MSSQL Oracle) Bro Bro , . . : - - . , . IDS , ; - . ; - . , ; Georgian Scientists/ . 6 N 3, 2024 4 - . , , ; - . . . , Bro libpcap . ) . , . , . . . Bro . Bro . Bro snort2bro , Snort Bro , . Bro . STAT STAT " " . STAT : STAT Framework - STAT ; MetaSTAT - STAT ; NetSTAT - UNIX ; USTAT - OS Sun Solaris- ; LinSTAT Linux ; WinSTAT - Windows ; logSTAT - UNIX syslog ; alertSTAT - ; web STAT Apache - . STAT . . , , , ) . „ “ . STAT- "Audit Analyzer Trace" . , Georgian Scientists/ . 6 N 3, 2024 5 , STAT . , . . , . Prelude Prelude IDS (Intrusion Detection System). Prelude GNU/Linux . Prelude , , . . , IDMEF (Intrusion Detection Message Exchange Format) . Prelude IDS Snort- , . OSSEC OSSEC IDS- . OSSEC- UNIX OS , , . OSSEC , , (rootkits) . , OS , , : SSH, MS Exchange, Sendmail ,Apache, ARP Watch, IIS, FTPD, Squid. OSSEC , , , OSSEC , IDS- . XML . OSSEC : , . . Georgian Scientists/ . 6 N 3, 2024 6 .2 OSSEC- . IDS . . Cisco Secure IPS Cisco Secure IPS , NetRanger, : - Cisco Secure IDS 4000 ; - Cisco IOS OS ; - Cisco Catalyst 6000 IDS Module ; - Cisco Secure Integrated Software (Cisco IOS Firewall Feature Set); - Cisco Secure IDS . - Cisco Secure Policy Manager; , . . . . RealSecure (IBM ISS) . Real Secure IBM- . RealSecure Georgian Scientists/ . 6 N 3, 2024 7 . , . , , , , , , . RealSecure . . . . , . . . , , , . . . , . . IDS- IPS- : IDS SPAN , Hub TAP IPS , IPS- . IDS- . IDS- , TCP Reset . , RealSecure Network Sensor- , Checkpoint Firewall- OPSEC . Symantec Network Security Symantec : Network Security 7100 Series Critical System Protection . Symantec- - IMUNE™ (Intrusion Mitigation Unified Network Engine). IMUNE™ Georgian Scientists/ . 6 N 3, 2024 8 : , (DOS) , . Symantec , . LiveUpdate- , . eTrust Intrusion Detection Computer Associates Computer Associates eTrust Intrusion Detection ( SessionWall) , LAN . . . eTrust Intrusion Detection- . - eTrust Intrusion Detection , , . , , , . , . . etrust . . eTrust Intrusion Detection , Java/ActiveX . , , . , . , . , Georgian Scientists/ . 6 N 3, 2024 9 , : , , , , . , . ) , ( , , , .). . , , , , . . 1. ., ., . . - „ - 2023“ , 12-13 , 2023 . .410-416. 2. Ledesma, Josue. “IDS vs. IPS: What Is the Difference?” Inside Out Security, October 23, 2018. https://www.varonis.com/blog/ids-vs-ips. 3. Andersen, I. (2023, November 22). Top 10 Most Common Types of Cyber Attacks. Https://Blog.netwrix.com/. https://blog.netwrix.com/2018/05/15/top-10-most-common-types-of- cyber-attacks/#Birthday%20attack Review and analysis of existing systems for detecting network attacks Summary Research in the field of detection of attacks on computer networks and systems has been conducted for a long time. Signs of attacks have been investigated, methods and means of detecting unauthorized access attempts have been developed and used through security systems, both on the Internet and at the local, logical and physical levels. Commercial intrusion detection systems by various foreign companies (Cisco, Snort, ISS RealSecure, etc.) are widely represented in the local market. Many local researchers use architectural analogues and typical solutions of already known systems. In recent years, the number of different types and methods of organizing unauthorized intrusion into computer networks has increased dramatically. Therefore, intrusion detection systems have become an important component of organizations' security infrastructure. This is facilitated by the Georgian Scientists/ . 6 N 3, 2024 10 appearance of a large number of literary sources, complex approaches and methods for detecting attacks in information systems. The purpose of the review of the existing network attack detection systems presented in the paper is to investigate the functionality of currently available IDSs and to reveal the shortcomings of the used attack detection methods and the disadvantages of their usability. Realizations of existing attack detection systems can be divided into two parts: research and commercial products. Each new research project is distinguished by the introduction of new methods of analysis and new approaches to the study of monitoring objects, although they quickly become obsolete. Commercial projects (such as ISS RealSecure, Symantec Network Security, Cisco IPS, etc.) remain relevant longer due to the support of manufacturers. The manufacturers provide ongoing customer support, new attack research, and signature updates. Therefore, it can be noted that most of the commercial research results are abuse detection systems, namely handwriting systems. Intrusion detection systems IDS (Intrusion Detection System) represent software and hardware- software solutions, where the processes of collection, storage and analysis (monitoring) of events occurring in a computer system or network are automated, and these events are independently analyzed in search of signs of information security violations. These protection systems exist as programs that can display a message that a network attack has occurred at that moment. Systems that are used to detect network attacks solve only one specific task - protection from an external attacker who tries to bypass protection systems and gain access to a local local network, but the problem of protection from internal threats remains an unsolved task. All known IDS are conditionally divided into three classes: - Network IDS (Network-based IDS, NIDS); - Nodal IDS (Host-based IDS, HIDS); - Hybrid IDS (Hybrid IDS). Node IDS can be further divided into two subclasses: system level IDS and application level IDS (application-based IDS). Keywords: Intrusion detection system Snort. Intrusion Detection System Bro. Intrusion detection system STAT. Prelude intrusion detection system. Intrusion detection system OSSEC. Hardware and software tool Cisco Secure IPS. Intrusion detection system RealSecure (IBM ISS). Intrusion detection system Symantec Network Security. System eTrust Intrusion Detection Computer Associates.