- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: What an audit system is more popular?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-25-2004 02:42 AM
06-25-2004 02:42 AM
Which kind of audit system is widely used, the basic one or high-level systems like HIDS?
What do you think?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-25-2004 03:35 AM
06-25-2004 03:35 AM
SolutionIt depends on what your tastes are like! HIDS is a very useful product and it comes with a GUI. This in itself can be a very useful feature for some and a put-off for others. HP-UX HIDS enables security administrators to proactively monitor, detect, and respond to attacks targeted at specific hosts. Since there are many types of attacks that can bypass network-based detection systems, HP-UX HIDS complements existing network-based security mechanisms, bolstering enterprise security. There is a nice whitepaper on HIDS, which talks abt its various features etc. It is available at:
http://www.hp.com/products1/unix/operating/infolibrary/briefs/intrusiondetectionpb.pdf
You can alternatively use Auditing. My vote is for HIDS. Am sure others have their own preferences.
Check out these links for similar discussions:
a) http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=556609
b) http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=616431
HTH.
Regards,
Sri Ram
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-25-2004 03:44 AM
06-25-2004 03:44 AM
Re: What an audit system is more popular?
At SEcurity class HP recommended a workstation be dedicated to be the HIDS server with the clients on all important servers and workstations.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-25-2004 06:06 AM
06-25-2004 06:06 AM
Re: What an audit system is more popular?
A HIDS (Host Intrusion Detection Systems) monitors event logs from multiple sources for suspicious activity. Host IDS are best placed to detect computer misuse from trusted insiders and those who have already infiltrated your network.
But...Now exist HIPS (Host Intrusion Prevention Systems).
It is the latest IDS buzzword which not only detect attacks but prevent them as well. Just as some NIDS went INLINE to block attacks, or just send TCP resets to close malicious connections (and are thus called Intrusion Prevention), some Host IDSes are now being proactively secure, implementing integrations with host firewalls.
Bruno
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-26-2004 08:38 PM
06-26-2004 08:38 PM
Re: What an audit system is more popular?
I vote for default Auditing subsystem. It's easily configurable, no GUI (you may like that feature ;-)) and a handy command 'audisp' to filter the records by user, event, system call, start date and time etc.,.
You can get better granularity with Auditing. I used HIDS also but I still prefer Auditing. The part I love is tracking the commands ran by the user. You can achieve it by enabling the system calls 'execv' and 'execve'. GUI can be painful if there are too many records though it does have a sort feature.
I heard from HP that they are going to combine the log files of Auditing and HIDS which will give us a choice to switch whatever we want.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2004 09:06 PM
06-27-2004 09:06 PM
Re: What an audit system is more popular?
Thanks for your fast responses!
Let me ask another question.
Since I have just 11.00 I would like to know is there any difference betwen Audits in
HP-Ux 11.00 and 11i?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2004 12:12 AM
06-28-2004 12:12 AM
Re: What an audit system is more popular?
http://forums1.itrc.hp.com/service/forums/questionanswer.do?admit=716493758+1088424657505+28353475&threadId=581780
Best Regards
Bruno
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2004 12:43 AM
06-28-2004 12:43 AM
Re: What an audit system is more popular?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2004 01:08 AM
06-28-2004 01:08 AM
Re: What an audit system is more popular?
mountains of documentaion. I got lost.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2004 02:34 AM
06-28-2004 02:34 AM
Re: What an audit system is more popular?
There are very few commands involved in Auditing. Man pages can help you a lot.
audsys - to manage auditing processes and files
audevent - to add/delete/display the events and system calls
auduser - to add/delete/display the users
audisp - to display audit records.
I couldn't notice any change in 11i's and 11.0 versions of auditing.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2004 02:43 AM
06-28-2004 02:43 AM
Re: What an audit system is more popular?
audisp involved). To make sure my app will work in 11i I need to know that audit file format is still the same. The problem is I didn't find anything about that on HP site.
thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2004 03:08 AM
06-28-2004 03:08 AM
Re: What an audit system is more popular?
Look at 11i release notes below. That should tell you the enhancements and changes from the previous release.
http://docs.hp.com/hpux/onlinedocs/B3920-90091/B3920-90091.html
If you don't find a mention about the particular component in that document, it's likely (not 100% though) that it remained same.
As far as Auditing is concerned, I didn't notice any difference between 11.0 and 11i including the format of the audit files.
-Sri