Blare IDS is an experimental opensource host-based Intrusion Detection System (IDS) based on taint marking analysis. It relies on an information flow policy defined at the operating system abstraction level (files, processes, sockets).
Unlike other IDSs such as Snort or Snare, Blare does not require attack signatures, learned profiles or knowledge of program behavior.
It is implemented in the Linux kernel as a LSM module, along with userspace tools. All the code of this project is released under the terms of the GPL license.
Android port.
Announces related to new versions, general information. Low traffic mailing list.
General discussions about Blare IDS.
Internal development mailing list.