Gentoo Archives: gentoo-server

From: Karl Zander <gentoolist@××××××××××××.com>
To: gentoo-server@g.o
Subject: Re: [gentoo-server] Intrusion Detection
Date: Mon, 15 Dec 2003 10:35:15
Message-Id: 5.1.0.14.2.20031215112844.03ba1898@mail.commpartners.com
In Reply to: Re: [gentoo-server] Intrusion Detection by Florian Huber
1 At 05:14 PM 12/15/2003 +0100, you wrote:
2 >> I think I read that AIDE was running on the Gentoo rsync server that was
3 >> comprised so running it does seem like good practice.
4
5 >IDS means intrusion DETECTION system, not PREVENTION! It cannot prevent
6 >you system from being compromized (but a good configuration and regular
7 >critical updates can...) - they only help you to understand what
8 >happened, e.g. which files have been altered by a rootkit. Same for the
9 >NIDS like snort and prelude...
10
11 >HTH
12 > Florian Huber
13
14 I understand its Detection, not Prevention. AIDE running on the rsync
15 server helped the security folks understand what happened. Prevention
16 would be a one inch gap.
17
18 -Karl