| Intrusion Detection Systems, Part IV: Logcheck |
| Source: FreeOS - Posted by Jen Olson | ||
|
But position yourself in this scenario: you have a tough security framework in place scanning almost every packet that tries to get into your network, you even have some of the most sophisticated Intrusion Detection Systems implemented for your whole network. However, you erred on the permissions of your log files and never bother to monitor the logs until you have been hit very hard. Of course, the well known distributions, work in a way such that they have certain scripts running in cron, which from time to time, tars the logs and back them up, so file permissions aren't anything you should worry about. You should also make sure that no one apart from root, has write access to the logs. Read this full article at FreeOS
Only registered users can write comments. Powered by AkoComment! |
||