What is Tripwire?
Tripwire is a form intrusion detection system (IDS) that helps you keep tabs on the integrity of the files on your computer. Quite simply it will help identify files or modifications made to your system in the event someone compromised your system.
How does Tripwire work?
Tripwire works on a pretty easy to understand concept. Basically, when you install Tripwire on your linux box you tell it to scan your system and create a database of checksums and information. Once you have a good reference point or database setup, you then scan your system on a regular basis for modifications to your file system.
Why would I want run a file system integrity software?
If you have ever had your system compromised by a cracker, it's an extremely frustrating time. You never know what they have done, where they have been, or what files they have modified or installed. This type of application helps in the recovery process. Quite often crackers will installed a group of applications on your system called a rootkit. A rootkit overwrites many of your commonly used system files to help hide the tracks of the cracker, or leave a backdoor on your system so he can return at a later date. Often the types of files modified are ones such as ps and netstat. By installing their own version of applications like these they can hide the fact there is additional daemons and processes running the background.
How do I put Tripwire to practical use?
Tripwire can be configured to send you e-mails at a set time interval via Sendmail or SMTP. On small systems it wouldn't be unreasonable to have your system checked several times a day and have Tripwire e-mail you the results. If you don't want the results e-mailed you can store the information in a file for later review. I believe it is a handy tool to have the logs e-mailed to you, so a problem can be quickly identified.
Thought Tripwire won't protect you from hackers, it will help you identify the level of which your system has been compromised and if scanned at regular time intervals should help you reduce the amount of time for which your system has been compromised. If your system has been broken in to, then the best thing to do is isolate the machine from the network and rebuilt it from know good backups and try to determine the method of entry.
Ken Dennis
http://kendennis-rss.homeip.net/
Homeland security, airport security, Internet security ??" these days we???re... Read More
What is a Web Database?A web database is a database... Read More
Language development computer: Computer-based method for aiding language development seems... Read More
Whether you need to close a sale, gather end-user feedback,... Read More
The java programming language is becoming more and more popular... Read More
Microsoft CRM was designed to be easily customizable. Microsoft CRM... Read More
eStore Advantage allows front-office applications to communicate with back-office business... Read More
Handling character strings in Java is supported through two final... Read More
Microsoft Business Solutions CRM proved to be reliable solution in... Read More
Traditionally we were considering functionally rich systems, such as SAP,... Read More
Do you remember that frustrating feeling when you find an... Read More
After seeing many people complain about their weak Internet security... Read More
Microsoft Business Solutions Great Plains as new ERP for multinational... Read More
Microsoft Business Solutions Great Plains is marketed for mid-size companies... Read More
When you think... Read More
Microsoft CRM is relatively new player on the now becoming... Read More
This is a short article, written in question/answer/FAQ style to... Read More
.Net Framework is a platform or development environment to seamlessly... Read More
Microsoft Business Solutions ? Navision is an integrated solution for... Read More
Many Webmasters have never bothered to view their website's server... Read More
With any good luck and a good amount of hard... Read More
Corporate ERP/MRP selection might be tough one, especially considering very... Read More
Assertion facility is added in J2SE 1.4. In order to... Read More
One of the main reasons business owners and entrepreneurs use... Read More
In linux, one of great commands for finding out information... Read More
spotless home service Arlington Heights ..Microsoft Great Plains has substantial mid-market share in the USA... Read More
Usually, the easiest way to tell you have spyware is... Read More
Customer Relationship Management (CRM) is a strategy and processes used... Read More
If you look back to the history, you will see... Read More
Disclaimer: All the thoughts expressed are my views only! Your... Read More
According to a survey conducted by InfoTrends/CAP Ventures entitled "Content-Centric... Read More
Microsoft Great Plains ? ERM from Microsoft Business Solutions and... Read More
You would like to protect your documents, wouldn't you? Reasons... Read More
Each Industry and market niche has business specific and unique... Read More
Having from five to ten and more favorite screensavers is... Read More
Best Software Act! is very popular CRM for small and... Read More
In a previous article, I wrote about OpenOffice... Read More
Scrapbooks are very popular these days. I think that almost... Read More
Microsoft Great Plains and Microsoft Retail Management System (Microsoft RMS)... Read More
It won't matter how effective your WinRunner Team is if... Read More
Now that spyware is the single most dangerous threat to... Read More
Great Plains Purchase Order Processing (POP) module makes up one-third... Read More
Viruses and spyware usually show up on your computer one... Read More
Assertion facility is added in J2SE 1.4. In order to... Read More
Microsoft Business Solutions Great Plains is very good fit for... Read More
Is your PC is slow and wimpy? Then you need... Read More
After seeing many people complain about their weak Internet security... Read More
Introduction To ISDN, Part III: Configuring PPP PAP AuthenticationNow we... Read More
Here is some free software tools to help you build... Read More
RSS (Really Simple Syndication) is a way for a site... Read More
Software |