Re: securing a unix system - suggestions on checking for intrusions

Jim Cheetham <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <CA+2knqsRNBOGSoU_aUbPUxyS8oJdgABuPO4dv3MM-mpkHxXTDg@mail.gmail.com>
On Thu, Oct 6, 2011 at 7:09 PM, Cliff Pratt <[email protected]> wrote:
> I don't see the point of tripwire and the like. It's shutting the stable
> door after the horse has bolted. It's far better to stop the files being
> changed in the first place.

You cannot provide 'perfect' security on a useable system, therefore
you have to accept the possibility that someone will exploit a
weakness that you did not know about.

So, given that an attacker exists, would you like to have some chance
of detecting whether or not they have been attacking you (i.e. log
analysis) or have actually succeeded in modifying your system (i.e.
tripwire & friends)?

An alert from tripwire (assume it is 100% correct here) tells you that
your system has been compromised, and therefore before putting any
*new* important data on that system, you will probably choose to fix
it.

So tripwire and the like have a very good purpose. Where they can go
wrong is where the attacker knows that you are using tripwire, and
attacks tripwire as well. This doesn't work if you run tripwire
'properly' (i.e. from read-only media, on a snapshot of the system
disk rather than the live machine).

IDS systems like tripwire have a lot of value, but the cost of
implementing them needs to be compared to the losses from an attack.

-jim

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.