Tripwire: A File System Integrity Checker
7 Slides52.00 KB
Tripwire: A File System Integrity Checker
Introduction What is Intrusion Detection? Intrusion detection is the art of detecting inappropriate, incorrect or anomalous activity. Who is an intruder? An intruder is some entity accessing/using a system beyond their authority Why Intrusion Detection? To aid system administrators
Classification of tools aiding Intrusion detection Anomaly detectors Example Tripwire Misuse detectors
Why Tripwire? A scenario explaining how Tripwire can help the system administrators to detect any intrusion.
Design and Implementation of Tripwire High level operation
Tripwire: Modes of Operation Database Initialization Integrity Checking Database Update Interactive Database Update
Conclusion Any Questions?