1 |
Am Mittwoch, 18. Januar 2006 16:24 schrieb mir Johnson, Maurice E CTR |
2 |
NSWCDL-K74: |
3 |
> A good host based IDS (file integrity monitoring system) would |
4 |
> record any system level changes made. |
5 |
|
6 |
No such IDS records any changes in *file systems* if the running |
7 |
software has no access to root privileges. That is a important |
8 |
difference. |
9 |
|
10 |
> IT should be fairly trivial to |
11 |
> start of with a sterile environment prior to running your CSA and |
12 |
> inspecting the environment afterwards. |
13 |
> |
14 |
> Try Tripwire or AID. |
15 |
|
16 |
This is not a good idea because this IDS cannot monitor all system |
17 |
activities. The only reliable way to monitor all activities is to run |
18 |
this software in a sandbox. |
19 |
|
20 |
Best Regards |
21 |
Oli |
22 |
-- |
23 |
gentoo-security@g.o mailing list |