Host Intrusion Detection Systems (HIDS) are soft sensors to detect control application issues, internal or external intrusions, misuse as well as performance bottlenecks on key servers and HMI's.
Continuous availability of control applications is key to meeting revenue and service availability goals. Industrial Defender is unique in its ability to provide organizations with excellent visibility to the operation of the actual control applications. Passive security HIDS on control equipment listen for and report security related events to the Industrial Defender Console. They are specifically designed to consume minimal CPU and network resources, accommodating the needs of the installed base of older control platforms.
Industrial Defender uniquely provides security HIDS functionality that monitors the control application itself. The security and performance information available varies by control application, but parameters crucial to the operation of your systems such as message queue status, open sockets and abnormal exits are made readily accessible. Industrial Defender security sensors are being developed for all major control systems, allowing a single security solution to deployed enterprise wide. For a list of current and planned HIDS, or to collaborate with Industrial Defender on development of real-time sensors, contract your local representative, or info@industrialdefender.com.
Security sensors are available for Unix, Windows or Linux operating systems. In addition to specific control applications, the sensors report on platform specific information such as failed login attempts, password age, logged-in user counts, event log activity and insertion of removable media. They can also monitor critical system parameters such as applications files and report unauthorized changes.
SNMP sensors are used to monitor switches, routers and other networking gear recording traffic flows, throughput and equipment health. Many pieces of control equipment, including PLC's, robots and RTU's also support SNMP, so the sensors can also be used to monitor these devices.