what to monitor with host based ids?

what to monitor with host based ids?

Post by qa monke » Tue, 04 Jun 2002 05:32:20



im using openBSD 3.1 as a bridge/packet filter and I recently added
fcheck to monitor directories and files.  I set it up to monitor the /etc
directory.
What other directories should I monitor for changes?

thanks,

-bob

 
 
 

what to monitor with host based ids?

Post by RSmith65 » Tue, 04 Jun 2002 10:04:25


I would monitor: /etc /bin /sbin /usr/sbin and the crontab directory.  If I
could, I'd probably add /usr/bin /usr/local/sbin /usr/local/bin, but these
aren't as important.

Just my $.02.

Roger

 
 
 

what to monitor with host based ids?

Post by Damian Mensche » Wed, 05 Jun 2002 05:24:15



> im using openBSD 3.1 as a bridge/packet filter and I recently added
> fcheck to monitor directories and files.  I set it up to monitor the /etc
> directory.
> What other directories should I monitor for changes?

Monitor everything, for starters.  Then stop monitoring things that
change too much to be worth monitoring.

Damian Menscher
--

-=#| 488 LLP, 1110 W. Green St, Urbana, IL 61801 Ofc:(217)333-0038 |#=-
-=#| 1429 DCL, Workstation Services Group, CITES Ofc:(217)244-3862 |#=-

 
 
 

what to monitor with host based ids?

Post by Tony Earnsha » Tue, 11 Jun 2002 05:11:46



> Monitor everything, for starters.  Then stop monitoring things that
> change too much to be worth monitoring.

Quite. Go read the SANS (www.sans.org, www.giac.org) info. for a month,
then start on your project. If, by then, the two nice young men in the
clean white coats haven't come to take you away to the funny farm, where
life is beautiful all the time ...

Best,

Tony

--

Tony Earnshaw

e-post:

www:
        http://www.billy.demon.nl
gpg public key: http://www.billy.demon.nl/tonni.armor

Telefoon:
(+31) (0)172 530428
Mobiel:
        (+31) (0)6 51153356

GPG Fingerprint = 3924 6BF8 A755 DE1A 4AD6 FA2B F7D7 6051 3BE7 B981
3BE7B981

 
 
 

1. Host-based IDS for Alpha platform?

I'm supposed to research host (and network, for that matter) based
intrusion detection systems that run on SGI, Solaris and NT for Alpha.
I'm pretty sure the first two aren't a problem, but does ANYONE support
NT on Alpha??? Yes, I know that Compaq doesn't support Alpha and I know
that Microsoft isn't supporting new versions, but we've got what we've
got.
I heard that Axent might run on Alpha, but I want something more than
just a simple log scraper like ITA.

Shayne

Sent via Deja.com http://www.deja.com/
Before you buy.

2. prevent return code going to stdout

3. Host based IDS a la tripwire/cops/tiger

4. why telnet not working with slip connection?

5. Host IDS and a Network IDS

6. NCSA httpd ~user config

7. Name-based vs IP based virtual hosts

8. Users other than root - printing and Netscape configuration

9. Mixing IP-based and name-based virtual hosts?

10. Can IP-based and Name-Based Virtual Hosting coexist

11. Host-based vs Controller-based RAID

12. Setting up IP-based and Name-based virtual hosting side by side...

13. name based vi IP based virtual hosts