hack proofing linux a Guide to Open Source Security phần 5

AntiVir quét các tập tin bạn chỉ định bằng cách sử dụng tập tin định nghĩa virus của nó, mà nằm ở / usr / lib / AntiVir / . Chạy mà không có đối số, AntiVir sẽ quét các thư mục hiện hành. Đối với một máy quét rộng lớn hơn, bạn phải chỉ định | Implementing an Intrusion Detection System Chapter 4 253 Figure Viewing SnortSnarf Output ACID requires the following items in addition to Snort Apache Server PHP version 4 The Snort database plug-in For more information consult any one of the ACID home pages. 254 Chapter 4 Implementing an Intrusion Detection System Summary In this chapter you have implemented an IDS on your have installed two host-based IDS applications Tripwire and PortSentry as well as a network-based IDS Snort . Now you can begin logging and analyzing connections for attacks and you can proceed with a bit more confidence now that you have implemented some safeguards. Additional IDS applications exist of course. In time the open source community will create and adopt even more sophisticated tools to help you make your network more secure. Several tasks lie now get to 1. Read even more logs than before you read this chapter. 2. Deploy the IDS applications you have read about on systems in your network. 3. Secure your IDS application elements such as your PostgreSQL database so that none of these elements can be compromised. For example if you are logging to a remote database or file find a way to secure the connection between the two hosts. 4. Monitor network and or performance to make sure that your IDS is not significantly affecting performance. So even though an IDS helps you do your job it will never be able to do your job for open source community has done a fairly good job keeping current with the latest IDS demands. As the Linux kernel and operating system stabilizes further chances are that you will be able to implement even more sophisticated solutions. Solutions Fast Track Understanding IDS Strategies and Types 0 An Intrusion Detection System IDS is any system or set of systems that has the ability to detect a change in the status of your system or network. Because an IDS can contain multiple

Không thể tạo bản xem trước, hãy bấm tải xuống
TỪ KHÓA LIÊN QUAN
TÀI LIỆU MỚI ĐĂNG
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.