LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-24-2003, 02:17 PM   #1
zuessh
Member
 
Registered: Jun 2002
Location: USA
Distribution: Suse 8.0
Posts: 247

Rep: Reputation: 30
Ids?


Any suggestions on a simple IDS app? Nothing too fancy or detailed. I have a ftp box set up in a dmz and would like to see just the basic traffic that comes and goes, identifying thing like port scan and the such would be nice but not necessary. BTW im using slack and proftp. Thx
 
Old 04-24-2003, 05:17 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
If you just want to monitor traffic, try ethereal/tcpdump. It's pretty simple to setup and even easier to use. If you want an IDS to actually detect intrusions (file alterations), tripwire is pretty simple to install. Unfortunately the default config has entries for almost everything so you'll have to modify the tripwire config file. www.linuxsecurity.com has some others under the packetstorm section.
 
Old 04-25-2003, 03:11 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Or if you don't want/need to inspect packets contents, why not use your fw with just a few LOG target rules.

AFAIK tripwire ain't (N)IDS, but a filesystem integrity checker like Aide, Samhain, Osiris, Integrit etc etc.
 
Old 04-25-2003, 08:27 AM   #4
zuessh
Member
 
Registered: Jun 2002
Location: USA
Distribution: Suse 8.0
Posts: 247

Original Poster
Rep: Reputation: 30
I told wrong. this box is actually suse 8.0, which comes with a firewall. I've never used this firewall, from others experience will this basically do the trick? Changing what I posted earlier, I would like to know if I am being attacked, but again nothing too detailed or fancy. Thanks for the help.
 
Old 04-25-2003, 09:20 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Oh well. If you want attack logging, dependant on your definition of that tho, and "nothing too detailed or fancy" why not just run Snort, and disable all the preprocessors and rulesets you don't want to have alerts for?
 
Old 04-25-2003, 09:42 AM   #6
zuessh
Member
 
Registered: Jun 2002
Location: USA
Distribution: Suse 8.0
Posts: 247

Original Poster
Rep: Reputation: 30
I know snort is ultimately the answer but it seems here lately that snort has had several vulns. In your opion if it is safe enough I will go ahead and try it.
 
Old 04-25-2003, 12:18 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'd say go ahead, but go for Snort-2.0x.
If you have questions about Snort configuration, just ask (but plz RTM first) and if you still think running Snort is a major risk you could try running it from a chroot.

Also plz note the 1st thread of this forum has a section on IDSes with much nfo on Snort.
 
Old 04-25-2003, 01:30 PM   #8
zuessh
Member
 
Registered: Jun 2002
Location: USA
Distribution: Suse 8.0
Posts: 247

Original Poster
Rep: Reputation: 30
thx, you da' man... even way back from the linuxbox days...
 
Old 04-25-2003, 02:32 PM   #9
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
From www.tripwire.org:

"Tripwire is originally known as an intrusion detection tool, but can be used for many other purposes such as integrity assurance, change management, policy compliance and more."

You do have a point though, that tripwire can only detect file alteration and therefore is much more limited in it's ability to detect intrusions. But often intrusions=file alteration, so I still think it's a useful tool to have around.
 
Old 04-26-2003, 05:48 AM   #10
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
thx, you da' man... even way back from the linuxbox days...
LOL, you remembered.... Seems like ages ago.

From www.tripwire.org:
"Tripwire is originally known as an intrusion detection tool, but can be used for many other purposes such as integrity assurance, change management, policy compliance and more."


Yeah, you're right to quote that, tho I never questioned tripwire's value or usefulness. I'll just say to me the acronym IDS is a bit misleading labelling this type of app. IMHO it would be less confusing if these apps where labelled as "filesystem integrity detection systems". I just hope ppl don't rely on this (passive detection method) as their sole means of detecting changes...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
pci.ids ?? matrixon Linux - Hardware 10 04-27-2005 07:08 PM
Ids Tredo Linux - Security 2 11-26-2004 02:13 PM
IDS for SUSE dominant Linux - Security 3 01-17-2004 12:15 PM
help about IDS and firewall Babba Linux - Security 2 02-11-2003 05:35 AM
IDS howto ? clanx Slackware 0 02-03-2003 08:48 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration