Re: HIDS recommendations?



Samhain?

Never tried it, but looked at it a few times.

Cheers,

Eric

On Sat, Jul 11, 2009 at 08:18:38PM -0400, Andrew Reid wrote:

Hi all --

I run a small network of several hosts, mostly Debian, and
I've become frustrated with the host-based intrustion detection
system I'm using. It works, but the GUI tools is very slow,
and package/security updates generate a lot of noise. We're
expanding the number of hosts we monitor, and it seems to be
scaling poorly.

In my ideal world, I'd like a Debian-smart integrity
checker.

Basic features:

- FOSS. I don't mind paying money for support or docs,
but I'd like the code to be open.
- Separate central monitoring host, integrity agents on
client hosts.
- Tunable/configurable to ignore rapidly-changing files,
give low-severity for enlarged/rotated log files,
good SUID and world-writable detection.


Desirable features:

- A fast, intuitive GUI that lets me isolate false positives
quickly (you can never tune these things perfectly),
and preferrably allows browsing by directory tree.


Dream feature:

- Debian-smart, so when I do security updates, it automatically
white-lists the files changed by the package manager, and
doesn't bug me about them.

I have direct experience with Samhain/Beltane/Yule, tripwire,
and recently road-tested ossec. They all do the basic features,
and S/B/Y and ossec have web-based GUI interfaces, but they seem
clunky to me, and scale poorly -- I end up manually scanning huge
lists of violations by eye, looking for the change that's *not* in
the /usr/changed-package/zillion-files tree, which is error-prone.

Searching the Debian package lists, I see references to "osiris"
"aide", and "prelude", although prelude appears to be more of a
combined log-analyzer and network IDS, and what I really want is a
file-system integrity tool.

A good GUI for tripwire might meet the need, and I'd also be
interested in people's experience with other tools, particulary for
monitoring about 50 hosts.

-- A.

--
Andrew Reid / reidac@xxxxxxxxxxxxxxxx


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx


--
Eric Gerlach, Network Administrator
Federation of Students
University of Waterloo
p: (519) 888-4567 x36329
e: egerlach@xxxxxxxxxxxxxxxxx


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: Woody on 486 problem
    ... Remember when Win95 ran well with 16MB RAM? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ... Its strange that older debian distributions are failing to properly ... And all I need is just simple network client without gui or any services:) ...
    (Debian-User)
  • Re: question about avoid duplicated ip address
    ... Maybe offtopic but I want to ask you is there is something to avoid ... duplicated ip address on the same network. ... My scenario is a big debian ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Rmore details on network was Setting up a network Was: Re: a very carefully asked question?
    ... While I had debian, of course I had equally no idea what was and was not included. ... However debian did find the other active hardware, meaning if debian can find a network card not connected to a network it may be there. ... narrowing it down to whether it is a cabled or wireless connection ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • Re: Slow Network Connection
    ... I tried installing Debian 4.0r0, 4.0r1 and a nightly test build and they ... if I boot off of a PCLinuxOS Live CD the network works perfectly. ... modprobe eepro100 ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Multihomed Question
    ... is also possible for hosts to have more than one IP ... have only one iface, eth1, used for a network. ... rest of the interfaces are usb, ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)