RE: using HIDS for change control

From: Andrew Plato (andrew.plato_at_anitian.com)
Date: 08/26/05

  • Next message: Olaf Gellert: "Re: Open Source IDS Solution?"
    Date: Thu, 25 Aug 2005 21:43:24 -0700
    To: "Rivera,Angel L." <ARIVERA@mitre.org>, <focus-ids@lists.securityfocus.com>
    
    

    If you just want to monitor changes, Tripwire does this. However, that
    is all it does. Its an "after the fact" intrusion detection.

    If you want active detection and file change detection, RealSecure
    Server Sensor does this. It can do in-line, real time IPS and monitor
    the file system for changes. And there is a version for both Windows and
    UNIX.

    DISCLAIMER: I sell these solutions.

    ___________________________________
    Andrew Plato, CISSP
    President/Principal Consultant
    ANITIAN ENTERPRISE SECURITY

    3800 SW Cedar Hills Blvd, Suite 280
    Beaverton, OR 97005
    503-644-5656 Office
    503-214-8069 Fax
    503-201-0821 Mobile
    www.anitian.com
    ___________________________________

    GPG fingerprint: 16E6 C5B0 B6CB F287 776E E9A9 AF47 9914 3582 633D
    GPG public key available at: http://www.anitian.com/corp/keys.htm
     
     

    -----Original Message-----
    From: Rivera,Angel L. [mailto:ARIVERA@mitre.org]
    Sent: Wednesday, August 24, 2005 3:10 PM
    To: focus-ids@lists.securityfocus.com
    Subject: RE: using HIDS for change control

    Does anyone on this list know of a sponsor that is using HIDS to monitor
    changes to a system's (Unix & Windows) configuration?
     
    The goal is to build a server according to specs (this would include
    hardening of the OS + agency specific security settings) then use a HIDS
    to detect and alert on any changes.
     
    Theoretically speaking, I know this can be done, but is anyone doing
    this?

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Olaf Gellert: "Re: Open Source IDS Solution?"

    Relevant Pages

    • Re: X.org 6.9
      ... To get my X work again I removed all entries in the section Monitor ... EndSection ... it seemed to cause problems with the auto detection of xorg. ... The system boots to login properly, but will not startx to KDE. ...
      (freebsd-stable)
    • Re: display issue
      ... You can enter the monitor settings by hand if you have the specs for it, ... remove detection database and re-init the ... DDC detection is switched off in this case ... > install procedure a second chance, it locked up last time while ...
      (alt.os.linux.suse)
    • Re: xorg.conf
      ... Ive had the monitor for 6 or 7 years and the monitor is a recognised model supported by system-config-display. ... I will set up a bugzilla bug for this. ... is the case for auto detection nowadays) if it's not found when adding ... Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines ...
      (Fedora)
    • RE: sys admin network monitor
      ... > I am looking for an open source piece of software that will monitor all ... > Is there anyone out there that is familiar with CA's E Trust Intrusion ... > Detection and a possible open source alternative. ...
      (Fedora)
    • RE: HIDS - new technologies ?
      ... There has been some work on doing intrusion detection systems that are ... For the Linux environment, for example I am aware of three or four such ... Cylant Secure is a HIDS that places sensors in side ... possible to write a program which monitors for executable files and when ...
      (Focus-IDS)