Host - PowerPoint PPT Presentation

1 / 9
About This Presentation
Title:

Host

Description:

... Based Intrusion Detection 'Working of Tripwire' 2. Background. Complements ... Complements a layered security approach. The generated report is small in size. ... – PowerPoint PPT presentation

Number of Views:29
Avg rating:3.0/5.0
Slides: 10
Provided by: skul3
Learn more at: http://www.cs.fsu.edu
Category:
Tags: complements | host

less

Transcript and Presenter's Notes

Title: Host


1
Host Based Intrusion Detection
  • Working of Tripwire

2
Background
  • Complements ... A Layered Security Approach
  • Firewalls / VPNs
  • Anti-virus
  • Authentication
  • Intrusion Detection System2

3
Uses
  • Intrusion Detection
  • File Integrity Assessment
  • Damage Discovery (Forensics)
  • Change / Configuration Management
  • System Auditing
  • Policy Compliance

4
How TripWire Software Works
Tripwire Reports
Baseline Database
1.
3.
Current System
Tripwire Software
2.
5
Steps Involved to Setup TripWire
  • Installation
  • Policy Creation
  • Generating Reports

6
A Simple Policy File
/etc R
all these files should be read only. /sbin
R12
but, be extra careful with these. /var/spool/mail/
maillog gt this file
should only grow
7
Pros and Cons of TripWire
  • Pros
  • Complements a layered security approach.
  • The generated report is small in size.
  • Running of TripWire is periodical and at the
    administrators discretion.
  • Cons
  • Lack of real time capability.

8
Properties and Services of an OS
  • Process
  • Process time
  • State of process
  • Number of blocked processes
  • Number of running processes
  • Thrashing rate
  • Memory
  • Amount of memory used
  • Address range of the memory used

9
Properties and Services of an OS
  • File
  • File size
  • File access permissions
  • Total disk space used
  • Number of files
  • IO
  • Number of IO operations (user, root, process)
  • Source and destination of IO
  • Total amount of data exchange between the
    channels
  • Bus utilization
Write a Comment
User Comments (0)
About PowerShow.com