Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Prelude Hybrid IDS
Date: Sun, 15 Jun 2003 18:42:40
Message-Id: 1055702170.21557.1088.camel@simple
In Reply to: Re: [gentoo-hardened] Prelude Hybrid IDS by Michael Boman
1 Michael & List
2
3 First I'd like to say thank you for your ebuild submissions to the
4 ugzilla system. But I have to mention that while live CVS ebuilds are
5 very nice for developers/or the bleeding edge its pretty much
6 discourraged around here for a developer to introduce new live cvs
7 ebuilds unless its has a static ebuild counterpart to go along with
8 them. This is needed so the package can hopefully reach "stable" status
9 in portage eg: not ~arch
10
11 If however your willing to work with us on this and make static ebuilds
12 with versions that have digestable md5sums then I'd be happy to work
13 with you on getting these ebuilds commited to portage on your behalf, or
14 atleast the ones that are not assinged to another dev already.
15
16 On Sun, 2003-06-15 at 00:12, Michael Boman wrote:
17 > On Sat, 2003-06-14 at 03:30, Daniel Struck wrote:
18 > > Hello,
19 > >
20 > > I was just surfing around and found an interesting IDS:
21 > >
22 > > Prelude Hybrid IDS
23 > > (http://www.prelude-ids.org/)
24 > >
25 > > "Prelude is a new innovative Hybrid Intrusion Detection system designed to be very modular, distributed, rock solid and fast."
26 > >
27 > > Interesting facts about this IDS:
28 > >
29 > > "
30 > > we try to retrieve the "stimuli" and responses eventually associated to attacks at network level or at system level
31 > > ...
32 > > Centralizing, Archiving, and Normalizing logs in a secure way
33 > > ...
34 > > in practice we have as many sensors as possible (Prelude-NIDS, Centralized Syslogs, ...) deployed on the network which send their alerts to Security Managers.
35 > > ...
36 > > Counter-measure agents are generic agents run on the machines which must react in case of an attack.
37 > > ...
38 > > Libsafe is a preloadable library (through LD_PRELOAD directive or using an entry in /etc/ld.so.conf) which protect a program against the exploitation of vulnerabilities like buffer-overflows of bogus format string.
39 > > "
40 > >
41 > >
42 > > So, I would be interested:
43 > >
44 > > - Are there any efforts made to adapt Prelude-IDS to gentoo, maybe in relation with gentoo-hardened?
45 >
46 > I have ebuilds submitted to bug.gentoo.org and even better and updated
47 > ones in my local CVS repository (keep forgetting to submit them).
48 >
49 > > - Is anyone already using Prelude-IDS on gentoo?
50 >
51 > Yes, and I am already doing that.
52 >
53 > Thanks for the interest, I will update my bugs now... ;)
54 >
55 > (search for bugs submitted by michael [at] ayeka [dot] dyndns [dot] org
56 > to get them, or bug me privately ;) )
57 >
58 > Best regards
59 > Michael Boman
60 --
61 Ned Ludd <solar@g.o>
62 Gentoo Linux (Hardened)
63
64
65 --
66 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Prelude Hybrid IDS Michael Boman <michael.boman@××××××××××.com>