Checking for Changes with Integrity Scanners

An integrity scanner is a system that can detect unwanted software on a computer. For the purposes of this section, it’s essentially the same thing as an IDS. Software such as Tripwire and the Advanced Intrusion Detection Environment (AIDE) provide a number of options that can help you check the integrity of local Linux systems.

The right time to install an integrity scanner is just after you have set up a ­baseline configuration, before any such systems are made operational on a network. Unless a malicious user has penetrated the repositories for your selected Linux ­distribution, that integrity scanner should be able to establish baseline settings for your standard ­configuration.

The noted IDSs ...

Get Security Strategies in Linux Platforms and Applications, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.