From SUSE Linux Enterprise Server v11 for System z
Part of GEN006480
Associated with: CCI-001259
Without a host-based intrusion detection tool, there is no system-level defense when an intruder gains access to a system or network. Additionally, a host-based intrusion detection tool can provide methods to immediately lock out detected intrusion attempts.
Ask the SA or IAO if a host-based intrusion detection application is loaded on the system. The preferred intrusion detection system is McAfee HBSS available through Cybercom. If another host-based intrusion detection application, such as SELinux, is used on the system, this is not a finding.
Procedure:
Examine the system to see if the Host Intrusion Prevention System (HIPS) is installed
#rpm -qa | grep MFEhiplsm
If the MFEhiplsm package is installed, HBSS is being used on the system.
If another host-based intrusion detection system is loaded on the system
# find / -name
Install a host-based intrusion detection tool.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer