当前位置:网站首页>Host based intrusion system IDS
Host based intrusion system IDS
2022-07-03 17:03:00 【Brother Xing plays with the clouds】
experiment Linux platform CentOS System
Application background : As system administrator , They need a security mechanism , For example, the mechanism of detecting file tampering
What exactly does it detect ? The contents of the document 、 File properties
AIDE: The abbreviation of advanced intrusion detection system
How can it be achieved :AIDE By scanning the surface, one is tampered linux The server File system to build file attribute database
take The server File attributes and database conversion , Warn the index of the modified file !
You can see from above :ADIE The initial installation of must keep the data ‘ clean ’
After the system is installed , And no services are exposed on the Internet or even on the LAN
step : After installing the system ----- Broken net ------ Install at the terminal AIDE service ------ To configure
install The server End software aide
# yum install aide
Default profile /etc/aide.conf
The main protection rules in the configuration file are :FIPSR NORMAL DIR DATAONLY
FIPSR = p+i+n+u+g+s+m+c+acl+selinux+xattrs+sha256
jurisdiction :p The index node :i Link number :l user :u
Group :g size :s Modification time :m Creation time :c
ACL:acl SELINUX:selinux xattrs:xattr
SHA256/SHA512 Monitoring and (sh256 and sh 512)
Exclamation point before entry ! tell ADIE Ignore subdirectories or directory files
First run AIDE
Initialize first ADIE database
aide --init
according to /etc/side.conf Generated by configuration file /var/lib/aide/aidedb.new.gz The file needs to be renamed /var/lib/aide/aidedb.gz
First proofreading
# aide Run this command directly , If there are no parameters, it defaults to check Options
to update AIDE database
# aide --update
thank you ~~~~~
边栏推荐
- Kotlin学习快速入门(7)——扩展的妙用
- What is the material of 13mnnimor? 13mnnimor steel plate for medium and low temperature pressure vessels
- One brush 144 force deduction hot question-1 sum of two numbers (E)
- Arduino esp32: overall framework of lvgl project (I)
- New library online | cnopendata China bird watching record data
- What material is sa537cl2? Analysis of mechanical properties of American standard container plate
- Thread pool: the most common and error prone component of business code
- Pools de Threads: les composants les plus courants et les plus sujets aux erreurs du Code d'affaires
- One brush 149 force deduction hot question-10 regular expression matching (H)
- CC2530 common registers for timer 1
猜你喜欢
关于学习Qt编程的好书精品推荐
Analysis of variance summary
IDEA-配置插件
Arduino esp32: overall framework of lvgl project (I)
Kotlin学习快速入门(7)——扩展的妙用
NLP四范式:范式一:非神经网络时代的完全监督学习(特征工程);范式二:基于神经网络的完全监督学习(架构工程);范式三:预训练,精调范式(目标工程);范式四:预训练,提示,预测范式(Prompt工程)
Static program analysis (I) -- Outline mind map and content introduction
utfwry. Dat PHP, about ThinkPHP's method of IP location using utfwry address Library
What material is 12cr1movr? Chemical property analysis of pressure vessel steel plate 12cr1movr
Yu Wenwen, Hu Xia and other stars take you to play with the party. Pipi app ignites your summer
随机推荐
What is your income level in the country?
CC2530 common registers
utfwry. Dat PHP, about ThinkPHP's method of IP location using utfwry address Library
Résolution de l'instance d'assemblage - - affichage à l'écran en mode réel
[combinatorics] non descending path problem (number of non descending paths with constraints)
Build your own website (23)
數據分析必備的能力
数据分析必备的能力
New features of C 10
深入理解 SQL 中的 Grouping Sets 语句
[2. Basics of Delphi grammar] 2 Object Pascal data type
線程池:業務代碼最常用也最容易犯錯的組件
[combinatorics] polynomial theorem (polynomial theorem | polynomial theorem proof | polynomial theorem inference 1 item number is the number of non negative integer solutions | polynomial theorem infe
Static program analysis (I) -- Outline mind map and content introduction
[try to hack] active detection and concealment technology
C语言字符串反转
Informatics Olympiad all in one YBT 1175: divide by 13 | openjudge noi 1.13 27: divide by 13
Talk about several methods of interface optimization
[mathematical logic] equivalent calculus and reasoning calculus of propositional logic (propositional logic | equivalent calculus | principal conjunctive (disjunctive) paradigm | reasoning calculus)**
2022.02.14_ Daily question leetcode five hundred and forty