Re: File integrity checkers

From: David Douthitt (ddouthitt_at_cuna.coop)
Date: 05/19/04


Date: Wed, 19 May 2004 11:43:37 -0500

Roberto wrote:

> I've seen a few that are available (Tripwire, AIDE, Samhain,
> Integrit). Does somebody have any experience with them to say which
> one is better? Basically, what I need is something that can verify
> about 60-80 different machines (mainly Sun, Linux, Alphas, but a few
> others too), but from a centralized station.

Sounds like you need portability and centralized control.

Tripwire is the hands down favorite and usually first mentioned, but the
open source version is currently lagging in maintenance and was dropped
by Red Hat from their Advanced Server 3 release and from the Fedora
Core. Others may be dropping Tripwire as well. I believe that Tripwire
doesn't support a centralized operation either.

I recently examined Samhain, which supports the centralized model, as
well as the traditional host-only model.

AIDE I don't know too well; it is the most often "second choice"
mentioned and appears to be the first choice for a tripwire replacement.

However, in my estimation, Samhain is used most by large installations.
I'm currently seriously evaluating Samhain.

Realize, too, that Red Hat Advanced Server does not come with a
replacement for Tripwire. I don't know which of these have Solaris
support, or support for whatever the Alphas are running.

Note that whatever database you create has to be protected; I recommend
off-host storage and a read-only copy on CDROM.



Relevant Pages

  • Re: [Full-disclosure] Linux big bang theory....
    ... Tripwire: place the signatures on non-alterable storage, ... I've added a function to hide the script from showing up on Samhain ... in the logs to Samhain. ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Linux big bang theory....
    ... that a compromised machine can be difficult to impossible to clean properly - which has been known for a *long* time. ... Tripwire: place the signatures on non-alterable storage, ... I've added a function to hide the script from showing up on Samhain ... in the logs to Samhain. ...
    (Full-Disclosure)
  • RE: Samhain vs. Tripwire
    ... which runs in real time to detect changes immediately ... Subject: Samhain vs. Tripwire ... > Brent Stackhouse ...
    (Focus-IDS)
  • Re: File integrity checkers
    ... >>I've seen a few that are available (Tripwire, AIDE, Samhain, ... >versions of tripwire cannot handle too many files at once, ... but from a centralized station. ...
    (comp.unix.admin)
  • Re: Tripwire versions?
    ... By the way support at Tripwire told me that Tripwire Manager does not ... work with the OS version of TWS. ...
    (comp.security.unix)