Re: securing a unix system - suggestions on checking for intrusions
Jim Cheetham <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <CA+2knqsRNBOGSoU_aUbPUxyS8oJdgABuPO4dv3MM-mpkHxXTDg@mail.gmail.com> |
On Thu, Oct 6, 2011 at 7:09 PM, Cliff Pratt <[email protected]> wrote: > I don't see the point of tripwire and the like. It's shutting the stable > door after the horse has bolted. It's far better to stop the files being > changed in the first place. You cannot provide 'perfect' security on a useable system, therefore you have to accept the possibility that someone will exploit a weakness that you did not know about. So, given that an attacker exists, would you like to have some chance of detecting whether or not they have been attacking you (i.e. log analysis) or have actually succeeded in modifying your system (i.e. tripwire & friends)? An alert from tripwire (assume it is 100% correct here) tells you that your system has been compromised, and therefore before putting any *new* important data on that system, you will probably choose to fix it. So tripwire and the like have a very good purpose. Where they can go wrong is where the attacker knows that you are using tripwire, and attacks tripwire as well. This doesn't work if you run tripwire 'properly' (i.e. from read-only media, on a snapshot of the system disk rather than the live machine). IDS systems like tripwire have a lot of value, but the cost of implementing them needs to be compared to the losses from an attack. -jim _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug