Linux Hybrid IDS Setup Wanted
Budget: ₹12,500 – ₹37,500 INR
I am in Andhra Pradesh and would like to work with a fellow professional based either here or in neighbouring Tamil Nadu to harden one of my production servers by deploying a full-featured intrusion detection system. The machine currently runs Ubuntu LTS with basic iptables rules; beyond that, security is minimal.
The goal is to implement a hybrid IDS—both host-based (HIDS) and network-based (NIDS)—so I can monitor file-system changes, privileged commands, and network traffic from the same dashboard. Open-source stacks such as OSSEC/Wazuh for HIDS and Suricata or Snort for NIDS are perfectly fine, provided you integrate them cleanly and tune out false positives. Coupling the IDS with existing firewall rules, configuring automated alerts (e-mail or Telegram), and preserving detailed logs in Elasticsearch or another central store is part of the brief.
I will give you SSH access via a bastion host; everything else—including rule sets, dashboards, and alert scripts—should be built by you and documented clearly for future maintenance.
Deliverables (acceptance criteria)
• Working HIDS and NIDS agents reporting to a central manager on the same server
• Custom rules and thresholds adapted to my workloads, with false-positive rate below 5 % after a week of testing
• Integration with current iptables rules so detected threats can be blocked automatically
• Alerting configured to my e-mail and Telegram account, including a test message for confirmation
• Step-by-step documentation of the build, configuration files, and commands required to reproduce the setup
If you are based in Andhra Pradesh or Tamil Nadu and confident with Linux security hardening, firewall tuning, and IDS deployment, let’s get started.
The goal is to implement a hybrid IDS—both host-based (HIDS) and network-based (NIDS)—so I can monitor file-system changes, privileged commands, and network traffic from the same dashboard. Open-source stacks such as OSSEC/Wazuh for HIDS and Suricata or Snort for NIDS are perfectly fine, provided you integrate them cleanly and tune out false positives. Coupling the IDS with existing firewall rules, configuring automated alerts (e-mail or Telegram), and preserving detailed logs in Elasticsearch or another central store is part of the brief.
I will give you SSH access via a bastion host; everything else—including rule sets, dashboards, and alert scripts—should be built by you and documented clearly for future maintenance.
Deliverables (acceptance criteria)
• Working HIDS and NIDS agents reporting to a central manager on the same server
• Custom rules and thresholds adapted to my workloads, with false-positive rate below 5 % after a week of testing
• Integration with current iptables rules so detected threats can be blocked automatically
• Alerting configured to my e-mail and Telegram account, including a test message for confirmation
• Step-by-step documentation of the build, configuration files, and commands required to reproduce the setup
If you are based in Andhra Pradesh or Tamil Nadu and confident with Linux security hardening, firewall tuning, and IDS deployment, let’s get started.
Related categories:
Linux
Amazon Web Services
Ubuntu
Network Administration
Elasticsearch
Security
Network Security
Firewall