Re: how to verify whether an attack attempt is successful?

From: Kurt Seifried (bt@seifried.org)
Date: 01/15/03

  • Next message: detmar.liesen@lds.nrw.de: "RE: how to verify whether an attack attempt is successful?"
    From: "Kurt Seifried" <bt@seifried.org>
    To: "Yan Zhai" <yzhai@unity.ncsu.edu>, <focus-ids@securityfocus.com>
    Date: Wed, 15 Jan 2003 13:27:19 -0800
    
    

    > Is there any technology developed in this direction?

    If you mean reactive technology then there are things like host based IDS
    (tripwire, syscall logging, etc.). Generally if you get a report like
    "/etc/passwd changed" or "seteuid executed by user nobody" that's a good
    indication your system got penetrated. This is why people should log
    successful as well as unsuccessful security events (logins, file accesses,
    etc.).

    Kurt Seifried, kurt@seifried.org
    A15B BEE5 B391 B9AD B0EF
    AEB0 AD63 0B4E AD56 E574
    http://seifried.org/security/



    Relevant Pages

    • Re: Host based IDS methodology and testing
      ... Host based IDS methodology and testing ... >Any production experience with any of the above products, ... Time delays in reporting alerts are often very dependent on the ...
      (Focus-IDS)
    • RE: Host based IDS methodology and testing
      ... I've successfully deployed Snort as a HIDS on a number of production servers ... Host based IDS methodology and testing ...
      (Focus-IDS)
    • Re: IDS is dead, etc
      ... > wouldn't call 'em an IDS, I think they're something different, much ... the host. ... Ensure Reliable Performance of Mission Critical Applications ... Precisely Define and Implement Network Security and Performance Policies ...
      (Focus-IDS)
    • [fw-wiz] Corporate H/N IPS
      ... Two new categories will be Host and Network Intrusion Prevention Systems, ... IDS, they actively block traffic deemed as malicious, almost like a firewall ... previous names for a HIPS have included Network Node IDS ...
      (Firewall-Wizards)
    • RE: can tripwire be used for sensor integrity???
      ... We have lots of users who use IDS Informer in this way to ensure that the $$ ... not caught out by a sensor going off line without knowing. ... tripwire does not detect LKM trojans or tampering. ... of kernel integrity protection. ...
      (Focus-IDS)

  • Quantcast