
Home | Slides | Sessions | Sponsors | Hotel & Travel | FAQ | Fees | Co-Located Events
SUSE Workshop | Social Activities | Technology Showcase | Connect | Training | Video Streaming
SUSE Workshop | Social Activities | Technology Showcase | Connect | Training | Video Streaming
The Next Stage in Linux IDS - Prelude-IDS and AuditdGary SmithA host-based intrusion detection system (HIDS) detects changes to file system objects. When first initialized, most HIDS scan the file system as directed by the administrator and stores information on each file scanned in a database. Later the same files are scanned and the results compared against stored values in the database. Changes are reported to the user. While this technique of HIDS is useful, it does not provide other useful information: when the file actually changed, who changed it, and the mechanism of change. Using freely available Open Source Software, such as Prelude-IDS and auditd, it's possible to construct a HIDS that not only captures changes to file system objects, but also when the file changed, by whom it was changed and how it was changed. While useful for detecting intrusions after the event, HIDS can also serve many other purposes: integrity assurance, change management, and policy compliance. |
Who Are We?
The Linux Foundation is a non-profit consortium dedicated to the growth of Linux.More about the foundation...
Explore
Search / Browse
Home / News / Press
Blogs / Whitepapers
Events / Workgroups













