RE: using HIDS for change control

From: Rivera,Angel L. (ARIVERA_at_mitre.org)
Date: 08/25/05

  • Next message: huy tran: "Re: IPS technology question."
    Date: Wed, 24 Aug 2005 18:09:33 -0400
    To: <focus-ids@lists.securityfocus.com>
    
    

    Does anyone on this list know of a sponsor that is using HIDS to monitor
    changes to a system's (Unix & Windows) configuration?
     
    The goal is to build a server according to specs (this would include
    hardening of the OS + agency specific security settings) then use a HIDS
    to detect and alert on any changes.
     
    Theoretically speaking, I know this can be done, but is anyone doing
    this?

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: huy tran: "Re: IPS technology question."

    Relevant Pages

    • Re: A clean OS?
      ... If we do that, the Windows ... > "vague configuration parameters", ... >> faster with a GUI. ... > And that's an option in Unix, whereby it's not an option in Windows, ...
      (alt.computer.security)
    • RE: Real world experience with HIDS
      ... I work with a very large installation of ISS RSS 7.0 on UNIX & ... We currently have 200+ RSS/HIDS Agents on UNIX + Windows platforms, ... Real world experience with HIDS ...
      (Focus-IDS)
    • Re: remote printing to Windows XP from OpenServer 5.0.6
      ... > I'm in the middle of trying to upgrade my users's desktops from Windows ... After upgrading to XP this configuration no longer works; ... > printer in Unix. ...
      (comp.unix.sco.misc)
    • Re: How to determine path of executable?
      ... > inferior to the way they're typically done on UNIX because the UNIX ... > things on Windows the Windows way. ... It became logical to associate configuration ... I have to inform several people - I'm just the developer - but there ...
      (comp.unix.programmer)
    • RE: Host Based IDS Recommendations?
      ... AIDE is a similar-esque HIDS to Tripwire but works on Unix servers. ... It have server agent based features. ...
      (Focus-IDS)