Operating System - HP-UX
1822709 Members
3603 Online
109644 Solutions
New Discussion юеВ

Intrusion Detection System/9000

 
Gary Mc Adam
Occasional Contributor

Intrusion Detection System/9000

Looking for real world experience with IDS/9000 software running on 11i. We are investigating using IDS with a trusted system and NIS+ and would appreciate any lessons learned. Also, can the file alerts in IDS be used to replace Tripwire.

Thanks!
3 REPLIES 3
harry d brown jr
Honored Contributor

Re: Intrusion Detection System/9000

Mary,

Do a search using boolean on this:

ids AND tripwire

and get results like this:

http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x905cfd3f91d3d5118ff40090279cd0f9,00.html

live free or die]
harry
Live Free or Die
Steven E. Protter
Exalted Contributor

Re: Intrusion Detection System/9000

You need not stop using tripwire with IDS. They work in different ways and both provide useful information.

HP now puts tripwire in a depot, which means they support it.

I recommend taking an older HP-UX box and instead of retiring it or using it to store MP3 files, make it an IDS/9000 server. Make the rest of your boxes IDS/9000 clients.

If you configure server to monitor and check everything, it will have a big impact on almost any server's CPU and performance.

Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Gary Mc Adam
Occasional Contributor

Re: Intrusion Detection System/9000

Steven,
Thank you for your response.
Would you elaborate on the differences you mention between IDS and tripwire. Also, can't find the hp depot can you forward the link.
Thanks!