- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Host Intrustion Detection (HIDS) memory usage.
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2005 06:12 AM
02-16-2005 06:12 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2005 07:12 AM
02-16-2005 07:12 AM
SolutionPHKL_30588:
( SR:8606353439 CR:JAGaf14233 )
High kernel memory usage is sometimes observed when using HIDS.
This is an 11.11 patch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2005 07:33 AM
02-16-2005 07:33 AM
Re: Host Intrustion Detection (HIDS) memory usage.
Host IDS version is B.03.00.00
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2005 07:44 AM
02-16-2005 07:44 AM
Re: Host Intrustion Detection (HIDS) memory usage.
This product has never been very low profile on memory usage. How much it uses depends on what you ask it to do.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2005 07:45 AM
02-16-2005 07:45 AM
Re: Host Intrustion Detection (HIDS) memory usage.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2005 07:46 AM
02-16-2005 07:46 AM
Re: Host Intrustion Detection (HIDS) memory usage.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-17-2005 08:51 AM
02-17-2005 08:51 AM
Re: Host Intrustion Detection (HIDS) memory usage.
The 11.11 patch will not impact idscor's memory usage (although I encourage you to install the patch to avoid the memory leak in the kernel). idscor will dynamically allocate more memory in order to handle a higher throughput of system call activity to monitor for intrusions.
idscor memory size starts at around 60Meg and can grow to around 200Meg. I would be concerned if idscor continues to chew up memory beyond 200Meg over a couple of weeks, in which case there might be a memory leak.
For performance reasons, we process all activity in memory (vs temporarily storing activity on disk) to monitor the system.
We can consider making the max memory usage of idscor configurable, with the understanding that this could hurt performance or result in missed intrusions.
Not running the race condition template will improve the memory usage, but the buffer overflow (BO) template is no longer CPU or memory resource intensive as it was prior to V3.0, so you can consider still running the BO template.
Pierre