Writing, Supporting, and Evaluating Tripwire: A Publically Available Security Tool
نویسنده
چکیده
Tripwire is an integrity checking programwritten for the Unix environment that gives system administrators the ability to monitor le systems for added, deleted, and modi ed les. First released in November of 1992, Tripwire has undergone several updates and is in current use at thousands of machines worldwide. This paper begins with a brief overview of what Tripwire does and how it works. We discuss how certain implementation decisions a ected the course of Tripwire development. We also present other applications that have been found for Tripwire. These unanticipated uses guided the demands of some users, and we describe how we addressed some of these demands without compromising the ability of Tripwire to serve as a useful security tool. We also discuss the process of releasing, and then supporting, a widely available and widely used tool across the Internet, and how meeting users' high expectations a ects this process. How these issues a ected Tripwire, done as as an independent study by an undergraduate, is also discussed. Software tools that were used in developing and maintaining Tripwire are presented. Finally, we discuss problems that remain unresolved and some possible solutions.
منابع مشابه
Experiences with Tripwire: Using Integrity Checkers for Intrusion Detection
Tripwire is an integrity checking program written for the UNIX environment. It gives system administrators the ability to monitor file systems for added, deleted, and modified files. Intended to aid intrusion detection, Tripwire was officially released on November 2, 1992. It is being actively used at thousands of sites around the world. Published in volume 26 of comp.sources.unix on the USENET...
متن کاملDetecting and presenting errors for Swedish writers at work
The aim of this paper is to discuss the problems of detecting and presenting errors using computer supported language checking. The development of an language checking tool for Swedish to support writing at work will serve as an example. At The Royal Institute of Technology (KTH) in Stockholm, Sweden, there has been a project on developing a writing support environment for supporting the writin...
متن کاملEvaluation of Distributed File Integrity Analyzers in the Presence of Tampering
In this paper, the Collaborative Object Notification Framework for Insider Defense using Autonomous Network Transactions (CONFIDANT) is evaluated in the presence of tampering. CONFIDANT’s mitigation capabilities are assessed and compared with conventional file integrity analyzers such as AIDE and tripwire. The potential of distributed techniques to address certain tampering modes such as Pacing...
متن کاملUsing Independent Auditors for Intrusion Detection
USING EMBEDDED AUDITORS FOR INTRUSION DETECTION SYSTEMS A basic cornerstone of security is to verify the integrity of fundamental data stored in the system. This integrity checking is being achieved using integrity tools such Tripwire, which depend on the integrity and proper operation of the operating system, i.e. these applications assume that the operating system always operates correctly. W...
متن کاملTRIPWIRE: Mediating Software Self-Awareness
We propose TRIPWIRE as a framework that provides for the mediation of software self-awareness by supporting real-time assessment and response capabilities. Our approach is inspired by the recent success of automatic speech recognition systems, which can assess the likelihood of a potentially unbounded set of possible utterances and select the most likely candidate in real-time, given an underly...
متن کامل