LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-28-2011, 11:03 AM   #1
dman777
Member
 
Registered: Dec 2010
Distribution: Gentoo
Posts: 232

Rep: Reputation: 8
Aide or Tripwire?


Which one is more preferred, Aide or Tripwire? Doing some googleing I found posts on one versus the other but the posts were really old and outdated.
 
Old 04-28-2011, 11:40 AM   #2
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by dman777 View Post
Which one is more preferred, Aide or Tripwire? Doing some googleing I found posts on one versus the other but the posts were really old and outdated.
The best way to make an informed decision on which is better would be to install both (on separate systems, of course). Monitor their performance, compare results, and decide.
 
Old 04-28-2011, 12:27 PM   #3
imitheos
Member
 
Registered: May 2005
Location: Greece
Posts: 441

Rep: Reputation: 141Reputation: 141
Quote:
Originally Posted by unixfool View Post
The best way to make an informed decision on which is better would be to install both (on separate systems, of course). Monitor their performance, compare results, and decide.
+1

I liked aide better than tripwire, but as unixfool said try them and decide for yourself. Also another good choice is samhain.
Quote:
The Samhain host-based intrusion detection system (HIDS) provides file integrity checking and log file monitoring/analysis, as well as rootkit detection, port monitoring, detection of rogue SUID executables, and hidden processes.
As you see it does many other things besides integrity checking and it is very good. Try this one too.
 
Old 04-28-2011, 07:48 PM   #4
dman777
Member
 
Registered: Dec 2010
Distribution: Gentoo
Posts: 232

Original Poster
Rep: Reputation: 8
The thing that bothers me about aide is that the db file isn't really protected and they suggest keeping it on a seperate device along with it's bin files for protection. From what I read, Tripwire requires a key for it's db and it's also crypted. Has Aide updated to this also?

Isn't Samhain a fork of Snort? I was planning on installing snort so wouldn't make since to have them together, right?
 
Old 04-29-2011, 08:07 AM   #5
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by dman777 View Post
Isn't Samhain a fork of Snort?
No. There's no relation between Snort and Samhain.
 
Old 04-29-2011, 09:27 AM   #6
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Quote:
Originally Posted by dman777 View Post
The thing that bothers me about aide is that the db file isn't really protected and they suggest keeping it on a seperate device along with it's bin files for protection. From what I read, Tripwire requires a key for it's db and it's also crypted. Has Aide updated to this also?
There are ways to get the same functionality out of aide.

However I would say encrypted or not your database should be kept on read only media and stored safely.

nomb

P.S. - I do want to +1 samhain though. Or Osiris if you want to be able to handle it from a server/client perspective.

Last edited by nomb; 04-29-2011 at 09:30 AM.
 
1 members found this post helpful.
Old 04-29-2011, 09:40 AM   #7
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Quote:
Originally Posted by unixfool View Post
The best way to make an informed decision on which is better would be to install both (on separate systems, of course). Monitor their performance, compare results, and decide.
Hmm. Sounds like the school of Thomas Edison.

As far as the debate... Tripwire has a full-out commercial version, http://www.tripwire.com/, which really puts AIDE to shame.

But, as for me, I use AIDE because I can't afford that expensive crap. Plus, I never install aide ON the computer that I run it on. I always transfer a fresh copy over to run and spit out a database, and compare it to a known good one. I do this because really, if you are an 3LiT3 HaX0R, the first thing you will notice is that crontab -l has /bin/aide in it which would lead you to modify that /bin/aide to ignore any changes it finds and spit out an "Everything is OK" message.

So, TripWire is WAYYYYYYYYYYYYYYYY better, if you pay for it. But Aide is small and portable and gets part of the job done.
 
Old 04-29-2011, 09:54 AM   #8
dman777
Member
 
Registered: Dec 2010
Distribution: Gentoo
Posts: 232

Original Poster
Rep: Reputation: 8
Quote:
Originally Posted by szboardstretcher View Post
Hmm. Sounds like the school of Thomas Edison.

As far as the debate... Tripwire has a full-out commercial version, http://www.tripwire.com/, which really puts AIDE to shame.

But, as for me, I use AIDE because I can't afford that expensive crap. Plus, I never install aide ON the computer that I run it on. I always transfer a fresh copy over to run and spit out a database, and compare it to a known good one. I do this because really, if you are an 3LiT3 HaX0R, the first thing you will notice is that crontab -l has /bin/aide in it which would lead you to modify that /bin/aide to ignore any changes it finds and spit out an "Everything is OK" message.

So, TripWire is WAYYYYYYYYYYYYYYYY better, if you pay for it. But Aide is small and portable and gets part of the job done.
I went ahead with aide since it was free and it seems to have the same options(except cryptic database) as the open source tripwire(maybe a few more options really since tripwire made the open version pretty bare).

I see your point and that is what i was concerned about. What I did was i transfered the aide config file, binary(i run this copy), and database to a thumb drive and just plug it in and do a check/update when i feel like it(personal home pc). Does this sound like a good solution?

I wouldn't mind trying samhain out if gentoo would make a working ebuild for it. Samhain seems to leave the commercial version of tripwire in the dust(unless i'm miss reading the features).

Last edited by dman777; 04-29-2011 at 09:59 AM.
 
1 members found this post helpful.
Old 04-29-2011, 11:32 AM   #9
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
Tripwire AFAIK just a file integrity checker. Samhain is a Host-based Intrusion Detection System. An alternative to Samhain is OSSEC, which is another open source HIDS.
 
1 members found this post helpful.
Old 04-29-2011, 11:56 AM   #10
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Quote:
Originally Posted by OlRoy View Post
Tripwire AFAIK just a file integrity checker. Samhain is a Host-based Intrusion Detection System. An alternative to Samhain is OSSEC, which is another open source HIDS.
OSSEC's dashboard is a laugh though. It hasn't been updated in 3 years, and is pretty useless.

Samhain's Web Interface is spiffy though.

Actually, OSSEC's dashboard is the closest thing to completely pointless as tatas on a tree.
 
Old 04-29-2011, 12:22 PM   #11
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
Quote:
Originally Posted by szboardstretcher View Post
OSSEC's dashboard is a laugh though. It hasn't been updated in 3 years, and is pretty useless.

Samhain's Web Interface is spiffy though.

Actually, OSSEC's dashboard is the closest thing to completely pointless as tatas on a tree.
You're right in that OSSEC has pretty much abandoned their "dashboard," but they've done so in favor of using things like Splunk or SGUIL instead. I haven't tried Samhain, maybe I should. It looks like it has come a long way.
 
1 members found this post helpful.
Old 04-29-2011, 12:26 PM   #12
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Quote:
Originally Posted by OlRoy View Post
You're right in that OSSEC has pretty much abandoned their "dashboard," but they've done so in favor of using things like Splunk or SGUIL instead. I haven't tried Samhain, maybe I should. It looks like it has come a long way.
Splunk is nice. I will warn you though, if you use the trial version, and go over 500MB, it WILL DELETE ALL OLDER ENTRIES. So, you are really, really, really screwed if you were testing it in a production environment and got hacked and went over your limit. Just an FYI for anyone interested.

Thanks for mentioning SGUIL. That looks like a decent program for analysis.
 
Old 04-29-2011, 01:02 PM   #13
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by OlRoy View Post
Tripwire AFAIK just a file integrity checker. Samhain is a Host-based Intrusion Detection System. An alternative to Samhain is OSSEC, which is another open source HIDS.
Tripwire is actually considered a HIDS. It monitors for system changes. Checking for file integrity is still monitoring system changes. Samhain and the others just use different methods of detecting changes. They're all HIDS, as they monitor for intrusions on the hosts they're installed on.
 
Old 04-29-2011, 01:22 PM   #14
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
@szboardstretcher I forgot to mention that limit on the free version of Splunk, thanks.

@unixfool Maybe, but file integrity checking is just one way to monitor a host's security. Tripwire just seems too limited and calling it a HIDS to me is kind of like calling AV software a HIDS. Personally, I just think of a HIDS as having more functionality than just file integrity or just AV scanning. It's really just semantics, though.
 
Old 04-29-2011, 01:57 PM   #15
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by OlRoy View Post
@szboardstretcher I forgot to mention that limit on the free version of Splunk, thanks.

@unixfool Maybe, but file integrity checking is just one way to monitor a host's security. Tripwire just seems too limited and calling it a HIDS to me is kind of like calling AV software a HIDS. Personally, I just think of a HIDS as having more functionality than just file integrity or just AV scanning. It's really just semantics, though.
S'OK. I just wanted to inform that the security industry considers it to be a HIDS. In the raw sense, it is. Many US government agencies use Tripwire devices as HIDS. Although the features are limited, the agencies usually don't need something full-blown in such a tool, especially when they tend to interlace the network with other security tools that offer the capabilities they need.

The jist of it is that it depends on the user's needs. If all they need is file integrity checking and they already have a suite of tools that meets their needs in securing a network, Tripwire might just fit the bill. But to state that it isn't a HIDS because it isn't rich in features compared to similar tools...that's a bit of a reach. No offense. That's like saying that, compared to Sguil, BASE isn't a SEM because Sguil has more options. That's not quite fair.

This is why I say for OPs to test the software they have questions about and decide on their own. Their own testing should weigh more than internet suggestions, IMO.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Can someone post a sample aide.conf file here? For AIDE IDS abefroman Linux - Security 9 04-12-2008 08:18 AM
tripwire vs. aide ddaas Linux - Security 12 06-03-2005 11:43 AM
aide conf f1uke Linux - Security 1 07-29-2003 07:38 PM
tripwire reports /usr/sbin/tripwire changed alfaalfabeta Linux - Security 5 07-22-2003 05:52 PM
aide cuckoopint Linux - Security 3 04-22-2003 02:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration