Linux productivity magazine - Tripwire

Wednesday, 14 May 2003, 12:29 PM EST

Tripwire is an Open Source program created to monitor changes in a key subset of files identified by you, and report on any changes in any of those files. When changes are detected, you, as the sysadmin, can determine whether those changes occurred due to normal, permitted activity, or whether they where caused by a breakin. If the former, you can update the system baseline to the new files. If the latter, you can shut down and begin repair and forensic activities.

Tripwire's principle is simple enough. The sysadmin identifies key files and causes Tripwire to record checksums for those files. He also puts in place a cron job to scan those files at intervals (daily or more frequently), comparing to the original checksum. Any changes, additions or deletions are reported, so the proper action can be taken.

This issue of Linux Productivity Magazine is devoted to Tripwire, which can alert you quickly when there's an intrusion. So kick back, relax, enjoy, and remember that if you're an Open Source user, this is your magazine.

[ Read more ]




Spotlight

Internet of Things: Bracing for the data flood

Whether we think we should be connecting the IoT and our existing systems together or not, the basic imperative to extract business intelligence from the raw information will demand that the connection takes place.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Tue, Jul 28th
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //