
This is the Title of the Book, eMatter Edition
Copyright © 2007 O’Reilly & Associates, Inc. All rights reserved.
454
|
Chapter 13: Simple Intrusion Detection Techniques
Using Tripwire
Among the most celebrated and useful things to come out of Purdue’s COAST
project (http://www.cerias.purdue.edu/coast/) was the Unix integrity checker Trip-
wire, created by Dr. Eugene Spafford and Gene Kim. Tripwire was originally both
open source and free, but in 1997, Tripwire went commercial, and fee-free use was
restricted to academic and other noncommercial settings.
Happily, a couple of years ago, Tripwire, Inc. released “Tripwire Open Source, Linux
Edition.” Until Tripwire Open Source was released, the older Academic Source
Release (ASR) lacked features long available in commercial versions of Tripwire. The
current release of Tripwire Open Source is based on Version 2.2 of the commercial
product, which is now up to Version 4.5. Although it still lacks a few “enterprise”
features such as centralized management of multiple systems (Tripwire, Inc. under-
standably still wishes to differentiate its commercial product line), it is functionally
very similar to the commercial Tripwire for Servers.
Note that Tripwire Open Source is free for use only on noncommercial Unices (i.e.,
Linux and Free/Net/OpenBSD). In fact, it’s officially supported only on Red Hat
Linux and FreeBSD, although there’s no obvious reason why