Operating System - HP-UX
1833914 Members
2173 Online
110063 Solutions
New Discussion

Re: Can HIDS/9000 log FAILED attempts to change/mod files/directories?

 
Mike Nemeth
Advisor

Can HIDS/9000 log FAILED attempts to change/mod files/directories?

Its appear as if HIDS 2.1 can only:
"
* Monitors a specified set of files for successful change attempts.


* Monitors specified directories (with exclusion rules) for successful attempts to change the content or the addition/deletion of files in the directory and all subdirectories below it.


* Monitors for changes of owner or file permissions of the specified files, and logs an alert only if an actual change to the permissions or owner occurs."

Can it be set up to log FAILED attempts to change/mod files/directories?

I've been told this is a goverment requirment
for us per National Industrial Security Program Operating Manual .

When will version 2.2 be avalible and what
might it contain?

We are about to deploy HIDS and may wait
if version 2.2 will be out soon!
3 REPLIES 3
Pierre Pasturel
Respected Contributor

Re: Can HIDS/9000 log FAILED attempts to change/mod files/directories?

I assume you are referring to "8-604. Changes to Data (Integrity)" in the NISPOM.

HP-UX HIDS can not currently be configured to monitor for failed attempts. I will file this as an enhancement request for V3.0 (due out next Spring/Summer). V2.2 is currently scheduled to be available on software.hp.com at the end of September and will not contain this enhancement request.

Pierre
Mike Nemeth
Advisor

Re: Can HIDS/9000 log FAILED attempts to change/mod files/directories?

Thank you Pierre!
In your opion is it worth waiting until ver 2.2
to deploy fullyn HIDS?
We're plannig to set up test with one server and
10 client the weekend but full deployment
would not be until the september/october
time frame.
Pierre Pasturel
Respected Contributor

Re: Can HIDS/9000 log FAILED attempts to change/mod files/directories?

You can start familiarizing yourself with HIDS using V2.1, but I would strongly encourage you to upgrade to V2.2 in Sept/Oct, as there are numerous bug fixes in V2.2.

Pierre