Expand Cut Tags

No cut tags
topaz: (qwrrty)
[personal profile] topaz
What intrusion detection toolkits does the modern Unix admin typically turn to?  Here are some of the ones I'm aware of:
I gather that these choices are not mutually incompatible, either (e.g. Tiger appears to provide a framework that may include Snort, chkrootkit and possibly others).

Those of you who have explored this issue in more depth than I have: what tools do you use and why?  Have you actually experienced an attack while guarded by any of these tools, and how did they perform?

Date: 2008-02-19 07:41 pm (UTC)
ext_8707: Taken in front of Carnegie Hall (bofh)
From: [identity profile] ronebofh.livejournal.com
Tripwire (http://www.tripwire.com/products/enterprise/ost/)

Haven't used it since last millennium, though.

Date: 2008-02-19 08:39 pm (UTC)
ext_86356: (2632)
From: [identity profile] qwrrty.livejournal.com
Right, I was under the impression that tripwire was moneyware. Apparently I was mistaken?

Date: 2008-02-19 08:43 pm (UTC)
jss: (lopsa)
From: [personal profile] jss
Yes, you're at least partly mistaken; I've installed free Tripwire in the past. There's probably a vendor out there willing to send it to you and charge you large Professional Services fees for a full or partial body to maintain/monitor it, but the base code is free IIRC.

Date: 2008-02-19 08:44 pm (UTC)
ext_8707: Taken in front of Carnegie Hall (bofh)
From: [identity profile] ronebofh.livejournal.com
The link goes to the open source version. They also have the payware version.

Date: 2008-02-19 08:24 pm (UTC)
From: [identity profile] fengshui.livejournal.com
Also, many recent Linux distros have MD5/SHA sums for each file they include in their packages.

Date: 2008-02-19 08:41 pm (UTC)
jss: (lopsa)
From: [personal profile] jss
What previous responders have said. I've used chkrootkit, snort, and tripwire, as well as YASSP on Suns, plus md5 checksums of object or source code archives of stuff I've downloaded (not just for Linux, but for open source in general).

May 2018

S M T W T F S
  12345
6789101112
13141516171819
20212223242526
27282930 31  

Most Popular Tags

Style Credit

Page generated Mar. 5th, 2026 10:26 am
Powered by Dreamwidth Studios