LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-12-2013, 01:30 PM   #1
Rohant
Member
 
Registered: Oct 2011
Location: India, Mumbai
Distribution: RHEL, Fedora,Ubuntu, Centos, Windows XP & Windows 7
Posts: 44

Rep: Reputation: Disabled
intrusion detection system


Hi All,

I am currently Working on Centos 5.7 x64 os.

my servers in DC which are behind the firewall.

I want to setup an intrusion detection system in my network so that i come to know when some one try to or take unauthorized login on my server. clearly Hacking in to my servers from outside network.

we mentioned list of ips in "/etc/hosts.allow" which can take ssh of the server & deny ssh=all in "/etc/hosts.deny" file.

iptable rules are configured.

i want to setup a application that is Open source (free) which can detect an attack or someone tries to take an unauthorized access to my servers. if possible Web Interface to monitor activities.

if above incident took place the application / tool should mail my team or send sms.

i searched for OSSEC, SNORT & IDS tool. i read about but very confuse about setting alert rules on to that.

If some one having better suggestions please let me know.

wanted to secure my servers at higher level.

also if possible advice me on security for Linux Server & how can i secure my servers.

I am Really interested in Computer security & want to learn badly.

Thanks in Advance.

Last edited by Rohant; 02-12-2013 at 01:31 PM.
 
Old 02-12-2013, 02:26 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
Have a look at the sticky threads at the top of this forum. The information on intrusion detection should be useful. The reason the information you have seen is complicated is that there are a lot of things to consider when securing your system initially and then maintaining your systems and their security.

What problems did you have with SNORT and the other things you tried? If you post more information there are people who will be able to help.
 
Old 02-12-2013, 02:27 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
...in addition to what gilead said:

Quote:
Originally Posted by Rohant View Post
I am currently Working on Centos 5.7 x64 os.
Then it's 2 updates behind: current is 5.9.


Quote:
Originally Posted by Rohant View Post
i want to setup a application that is Open source (free) which can detect an attack or someone tries to take an unauthorized access to my servers. if possible Web Interface to monitor activities. if above incident took place the application / tool should mail my team or send sms.
What services are exposed through the DC firewall? Only SSH or what else? What have you done to secure and harden these servers except the firewall and tcp_wrappers?


Quote:
Originally Posted by Rohant View Post
i searched for OSSEC, SNORT & IDS tool. i read about but very confuse about setting alert rules on to that.
Set up a host where you can test things out on. (Doesn't have to be a hard disk installation: you could use virtualization like VMware, VirtualBox, QEmu etc, etc.) After reading the documentation install the application and configure it. Test if you can make it log an alert. If it doesn't work feel free to ask specific questions providing an account of the steps you took, configuration files, error output, log excerpts et cetera.


Quote:
Originally Posted by Rohant View Post
also if possible advice me on security for Linux Server & how can i secure my servers.
What have you searched for and read so far?
 
Old 02-13-2013, 08:02 AM   #4
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Quote:
I want to setup an intrusion detection system in my network so that i come to know when some one try to or take unauthorized login on my server. clearly Hacking in to my servers from outside network.
Upon reading this, the first thing that came to mind was getting to know your log files intimately. Understand what each of them do, how they are configured, and how different aspects of your system contribute to them. While this is undoubtedly covered in the intrusion prevention references, I think it bears special mention. In my opinion it is one of the most critical, active things you can do. As well as being the most often overlooked and ignored.
 
Old 02-13-2013, 06:51 PM   #5
jnihil
Member
 
Registered: Dec 2012
Location: inside the matrix
Distribution: Debian, Xubuntu, Gentoo, Antergos
Posts: 90

Rep: Reputation: 27
Quote:
Originally Posted by Noway2 View Post
Upon reading this, the first thing that came to mind was getting to know your log files intimately. Understand what each of them do, how they are configured, and how different aspects of your system contribute to them. While this is undoubtedly covered in the intrusion prevention references, I think it bears special mention. In my opinion it is one of the most critical, active things you can do. As well as being the most often overlooked and ignored.
I couldn't agree more. The log is your friend.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Intrusion detection system raji27 Linux - Software 2 09-10-2011 08:31 AM
Intrusion Detection System FredrikN Linux - Security 8 03-23-2007 01:54 AM
intrusion detection system aparna Linux - General 4 01-02-2006 09:30 AM
intrusion detection system aparna Linux - General 2 12-31-2005 01:03 AM
Network Intrusion Detection System WarlockofVirgo Linux - Security 1 08-08-2004 10:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration