Gentoo Archives: gentoo-server

From: Konstantin Arkhipov <voxus@×××××××.ee>
To: gentoo-server@g.o
Subject: Re: [gentoo-server] Intrusion Detection
Date: Tue, 16 Dec 2003 02:20:21
Message-Id: 20031216111620.3c0f3e22.voxus@infonet.ee
In Reply to: [gentoo-server] Intrusion Detection by Karl Zander
1 On Sun, 14 Dec 2003 20:48:21 -0500
2 Karl Zander <gentoolist@××××××××××××.com> wrote:
3
4 > The Gentoo Security Guide seems to recommend AIDE (Advanced Intrusion
5 > Detection Environment) . And I would like to run that. But given that
6 > files in /bin, /sbin or /etc or other important places that AIDE may be
7 > monitoring can change when running emerge, how management intensive is it
8 > to run AIDE or any other intrusion detection?
9 >
10 > I think I read that AIDE was running on the Gentoo rsync server that was
11 > comprised so running it does seem like good practice. Just trying to get
12 > a handle on what management tasks I will need to think about to make AIDE
13 > most useful.
14 >
15 > -Karl
16 >
17 >
18
19 take a look at cfengine -> http://www.cfengine.org/
20
21
22
23 --
24 voxus
25 :wq

Replies

Subject Author
Re: [gentoo-server] Intrusion Detection Andrew Cowie <andrew@×××××××××××××××××××.com>