1 |
The Gentoo Security Guide seems to recommend AIDE (Advanced Intrusion |
2 |
Detection Environment) . And I would like to run that. But given that |
3 |
files in /bin, /sbin or /etc or other important places that AIDE may be |
4 |
monitoring can change when running emerge, how management intensive is it |
5 |
to run AIDE or any other intrusion detection? |
6 |
|
7 |
I think I read that AIDE was running on the Gentoo rsync server that was |
8 |
comprised so running it does seem like good practice. Just trying to get |
9 |
a handle on what management tasks I will need to think about to make AIDE |
10 |
most useful. |
11 |
|
12 |
-Karl |