1823088 Members
3307 Online
109646 Solutions
New Discussion юеВ

HP-UX IDS System 9000

 
Leslie Fischer
Frequent Advisor

HP-UX IDS System 9000

We are getting ready to load the hp IDS/9000 software on a HP 9000 system. I am looking for comments from anyone who has worked with this software and has any words of wisdom, pros or cons of running this software in a production environment. Any gotcha's, noticeable performance issues? Thanks,
Leslie
3 REPLIES 3
harry d brown jr
Honored Contributor

Re: HP-UX IDS System 9000


Leslie,

As with any "extra" application running will consume resources. As far as gotcha's, I'd suggest first bringing your machine up-to-date with the latest patch bundle, then installing the software, then checking, with the custom patch manager for any extra patches you might require. UNfortunately I haven't played with IDS/9000, but maybe I will?
0 points here please. Good luck!

live free or die
harry
Live Free or Die
Bruce Laughlin
Frequent Advisor

Re: HP-UX IDS System 9000

Hi Leslie,

1) Be sure to read the admin guide and release notes carefully. You can find them at:
http://docs.hp.com/hpux/internet/index.html#Intrusion%20Detection%20System/9000

2) You must make sure that all the required patches are installed. This is well documented in the release notes, installation section.

3) Use of the race condition and buffer overflow templates can be very CPU intensive.

That's all for now,
Bruce Laughlin
Ray Brewer
Valued Contributor

Re: HP-UX IDS System 9000

IDS/9000 comes with several default templates that monitor for everything from file permissions to bad logins. If you are using OVO in your enviornment (formerly ITO, VPO, OPC, etc) and the system you are installing IDS/9000 on to has the OVO agent software installed, IDS/9000 will automatically be configured to send its messages to the OVO management server. This will flood the Management server with thousands of messages.

Also it is a bit trickey to make custom monitoring templates so when reading the documentation pay extra attention to this section.

Installation is very simple. Just a normal swinstall. You can expect it to use up to 10% of available system resources if you have it monitor for everything it's capable of doing but I think you'll find there are several things that you will not care to monitor.