LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How would you rate the importance of default settings in security?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: July 4th, 2008
Linux Security Week: June 30th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Intrusion Detection
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.



Log analysis for Intrusion detection document.  23 May 2006 
Source: OSSEC - Posted by Benjamin D. Thomas   
A new documet, titled "Log analysis for Intrusion Detection", is available. It shows how some threats can be detected by correlating specific patterns on web logs, proxy logs and authentication logs..

"Log analysis is one of the most overlooked aspects of intrusion detection. Nowadays we see every desktop with an anti-virus, companies with multiple firewalls and even simple end-users buying the latest security related tools. However, who is watching or monitoring all the information these tools generate? Or even worse, who is watching your web server, mail server or authentication logs?"

Write Comment

 
Targeted attack: experience from the trenches  19 May 2006 
Source: Sans.org - Posted by Benjamin D. Thomas   
Learning lessons from incidents is a very important part of incident handling. Yet with targeted attacks it is very hard as you need to have a case before you can learn. So learning from others is even more important in this case. Michael reported on an unnamed organization being hit by a limited, targeted attack. Detection is mostly the very hard part in these attacks. This case seems to have been detected by a very alert user detecting a domainname in an email that wasn't completely right.

Write Comment

 
Building a PHP Honeypot  16 May 2006 
Source: InfoSecWriters - Posted by Benjamin D. Thomas   
"From an attacker's viewpoint, a Web application is an interesting target for several reasons. First, the quality of the source code as related to security is often rather poor, as numerous bug reports show... Another factor is the applications' complex setup." [Holz06]

Recent years have seen a substantial rise in the number of attacks directed against web applications, such as SQL injection, cross-site scripting attacks (XSS) and other input validation problems such as remote file includes in some PHP applications, command injection in the XML-RPC library and in the awstats[Aws06] package. Partly this is because a great deal of application level code has been written, and some of it without much regard to security issues.

Write Comment

 
To Executives, Intrusion Defense Is A Hard Sell  27 April 2006 
Source: Search Security - Posted by Eric Lubow   
Network admin Doug Porter has conducted enough budget presentations to know that upper management types tune out when it comes to slides about spyware scanners, content filters and the growing sophistication of online criminals. His chances of getting badly needed intrusion defense resources always improve, however, when he talks to the top brass about inconveniences, like the spam clogging their e-mail queues.

Write Comment

 
Open Source Intrusion Detection and Prevention: Tools for Today's Corporate Market  27 April 2006 
Source: InfoSecWriters - Posted by Eric Lubow   
There are literally hundreds of reported network attacks each day. Our systems are being compromised by persons trying to intrude, stop, obtain or destroy our precious data. The ability to detect intruders and monitor the network systems that you operate is not just an option. The Sarbanes Oxley Act is a warning to our publicly traded companies that we are not going to be allowed to sit idle as corporate leaders or IT professionals while there might be huge gaps in our network defenses. Network tools for monitoring intrusion and tools to prevent intrusion can be completely cost inhibitive to a company that has not prepared to budget for their implementation or has little exposure to their use. This paper discusses two open source tools, Snort and Bro that are either no cost or low cost that you can obtain and train to use. These tools are designed to monitor traffic, analyze protocols, capture packets, map networks, port scan and prevent intrusion. Whether the attack is from the outside of your LAN or from the inside, do you have the tools and training to meet the demands of securing your network data?

Write Comment

 
"CSI" for the Enterprise?  27 April 2006 
Posted by Benjamin D. Thomas   
Michael Osborne has been getting a lot of vendor calls lately pitching a new breed of products, typically called electronic data discovery (EDD) tools. These tools promise to investigate historical data to uncover security breaches, compliance failures and plain old errors in transactions across various enterprise systems, from network administration to accounting. Driven by compliance requirements such as Sarbanes-Oxley and the Health Insurance Portability and Accountability Act, these tools focus on user activities, such as who accessed a database or updated a customer account.

Write Comment

 
Ideal Intrusion Defense Combines Processes And People  25 April 2006 
Source: Search Security - Posted by Eric Lubow   
A global IT service provider with 39,000 employees and thousands of computing devices is sure to be a tempting target for digital desperados. But which attack scenarios are most likely to keep the security chief up at night? Dave Bixler, CISO for Siemens Business Services Inc., a subsidiary of Munich-based Siemens AG, lists three:

# Spyware;
# Stolen or misplaced laptops with passwords that can be unlocked within minutes using any number of online tools; and
# Employees who load sensitive files onto USB keys and then lose them.

Write Comment

 
Finding software vulnerabilities with "honeyclients"  17 April 2006 
Source: TechWorld.com - Posted by Benjamin D. Thomas   
I've been a big fan of honeypots ever since I first learned about them in Clifford Stoll's The Cuckoo's Egg. His story about catching German hackers because of a 75-cent accounting error is a thrilling forensics journey. Today, I support honeypots because they are a must-have early-warning tool in any organisation. If you can't stop the hacker or malware - it's hard to be perfect all the time - the next best thing is early warning. Placing a honeypot within your enterprise network, next to other valuable assets, assures that any rogue outsiders - or insiders - will be discovered quickly. If the hacker or malware touches the fake asset, it's done. Low cost and low noise equals high value.

Write Comment

 
Case Of The Lucrative Lure  12 April 2006 
Source: itToolBox - Posted by Benjamin D. Thomas   
"Hand me the boot disk." I said as I motioned to Scrap with my right paw. My left paw was busy making sure that the IDE cables were securely fastened to the suspect's hard drive and the clone drive. "Ah, acquiring a drive in DOS with Encase. This is so old school." Scrap mumbled as he fetched an Encase boot disk from his site bag. The office was very quiet, and only the hum of the suspect's workstation could be heard above our breathing. It was late, much too late, for a couple of monkeys to be playing around in a client's office trying to acquire a hard drive image.

Write Comment

 
Honeypots - How to seek them out  06 April 2006 
Source: IT Observer - Posted by Benjamin D. Thomas   
To study the proceedings and attacks from hackers, Honeypots are used. The idea thereby is, to put one or more special servers in a network . An aggressor; who cannot differentiate between genuine server/services and honeypots; sooner or later will be taken up the services offered by a Honeypot by his search for a safety gap. All his activities on the honeypot are loged thereby.

Write Comment

 
<< Start < Prev 1 2 3 Next > End >>

Results 21 - 30 of 391
    
Partner:

 

Latest Features
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Meet the Anti-Nmap: PSAD
Open Source Tool of February: Nmap!
HowTo: Secure your Ubuntu Apache Web Server
Yesterday's Edition

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.