Linux productivity magazine - Tripwire

Wednesday, 14 May 2003, 12:29 PM EST

Tripwire is an Open Source program created to monitor changes in a key subset of files identified by you, and report on any changes in any of those files. When changes are detected, you, as the sysadmin, can determine whether those changes occurred due to normal, permitted activity, or whether they where caused by a breakin. If the former, you can update the system baseline to the new files. If the latter, you can shut down and begin repair and forensic activities.

Tripwire's principle is simple enough. The sysadmin identifies key files and causes Tripwire to record checksums for those files. He also puts in place a cron job to scan those files at intervals (daily or more frequently), comparing to the original checksum. Any changes, additions or deletions are reported, so the proper action can be taken.

This issue of Linux Productivity Magazine is devoted to Tripwire, which can alert you quickly when there's an intrusion. So kick back, relax, enjoy, and remember that if you're an Open Source user, this is your magazine.

[ Read more ]




Spotlight

How security analytics help identify and manage breaches

Posted on 30 July 2014.  |  Steve Dodson, CTO at Prelert, illustrates the importance of security analytics in today's complex security architectures, talks about the most significant challenges involved in getting usable information from massive data sets, and much more.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Thu, Jul 31st
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //