Detecting when you need to system rescue
Another problem I see more and more often is that less and less data is actually stored on traditional filesystems. Databases and NoSQL systems, such as MongoDB and Hadoop, are increasingly used to store data objects, and there's no easy way to apply tools like Open Source Tripwire or AIDE to them. Monitoring such systems for changes and integrity will require software that is not available yet. (Weirdly, I can't find anyone working on this, so let me know if you are!)
Even having a noisy system that you mostly ignore is better than having no detection at all. If a break-in or accident occurs, at least you'll be able to get some idea of the scope of it, and, if you're lucky, you'll be able to determine the actual damage and see how the breach occurred. Of course, these monitoring tools also need to be paired with a good data backup strategy so that you have something with which to restore your system.
Another benefit of tools like Open Source Tripwire and AIDE is that they can pinpoint exactly which files need to be restored (e.g., if files have the same hash value that they had last week, you don't need to worry) and thereby significantly reduce restore times.
- Open Source Tripwire: http://sourceforge.net/projects/tripwire/
- AIDE: http://aide.sourceforge.net/
- "Secure storage with GlusterFS" by Kurt Seifried, Linux Magazine, issue 153, August 2013: http://www.linux-magazine.com/Issues/2013/153/Security-Lessons-GlusterFS/(language)/eng-US
- "Kernel rootkits and countermeasures" by Jürgen Quade, Linux Magazine, issue 147, February 2013: http://www.linux-magazine.com/Issues/2013/147/Kernel-Rootkits/(language)/eng-US
- "Monitor file and directory activity with incron" by Paul Brown, Linux Magazine, issue 158, January 2014: http://www.linux-magazine.com/Issues/2014/158/Monitoring-with-incron/(language)/eng-US
Buy this article as PDF
“Xenial Xerus” comes with a new packages format and several improvements for the enterprise.
Linux users can now download and install the Windows code editor
New initiative will address security and interoperability concerns around container technology.
Developers can use RHEL as a development platform without a subscription fee.
Windows users will soon have native access to the Bash shell.
Improvements to SMTP will provide better guarantee of confidentiality
Graphics vendor embraces new reality in Linux graphics
Pioneer Ray Tomlinson bequeathed the @ sign to billions of Internet users
Redmond says its classic database tool will run without Windows
New intrusion technique affects most non-Bluetooth wireless mice