📄 00000008.htm
字号:
<HTML><HEAD> <TITLE>BBS水木清华站∶精华区</TITLE></HEAD><BODY><CENTER><H1>BBS水木清华站∶精华区</H1></CENTER>发信人: pure (青衣~ shadow in silence), 信区: Linux <BR>标 题: Re: Linux Intrusion Detection 0.4 released <BR>发信站: BBS 水木清华站 (Fri Nov 19 23:20:56 1999) <BR> <BR>sorry first. <BR>I want to propose some questions about your project. <BR>1: Your system name's object is Intrusion Protection System <BR> not Intrustion Detection System because you just add <BR> protect to some important files and such things. <BR>2: Your code is hard-coded in kernel, but better solution <BR> is to implement a complete security level in Linux, <BR> similar to FreeBSD's security level and everyboy may <BR> change it at fly. <BR>3: Doing a not-comptiable kernel patch which can't merge into <BR> official kernel is not very good thing for us. <BR> Just my opinions, free discussions are welcomed! <BR> <BR>【 在 vertex (lancelord) 的大作中提到: 】 <BR>∶<I> Linux Intrusion Detection System 0.4 release </I><BR>∶<I> --------------------------------------- </I><BR>∶<I> Linux Intrusion Detection System is a linux kernel patch </I><BR>∶<I> and modules to enhance the linux kernel security. It can </I><BR>∶<I> protect important files from being changed. When it's in </I><BR>∶<I> effect, no one (including root) can change the protected </I><BR>∶<I> files or directories and their sub-directories, and the </I><BR>∶<I> protected append-only files can only be appended. It can prevent </I><BR>∶<I> loaded modules from being unload, mounted filesystems from being </I><BR>∶<I> unmount and lauched processes from being kill. It can </I><BR>∶<I> also protect the hard disk's MBR, and can also disallow </I><BR>∶<I> sniffing while the NIC is in promiscuous mode. </I><BR>∶<I> For more detail , visit the homepage at </I><BR>∶<I> <A HREF="http://www.soaring-bird.com.cn/oss_proj/lids/">http://www.soaring-bird.com.cn/oss_proj/lids/</A> </I><BR>∶<I> 主要特征: </I><BR>∶<I> 1. 重要文件的保护 </I><BR>∶<I> 在生效的情况下,任何人包括 root 均不能改变受保护的文件. </I><BR>∶<I> 2. 重要 log 文件的保护 </I><BR>∶<I> log 文件只能增长.不能改变 </I><BR>∶<I> 3. 安全的文件系统 </I><BR>∶<I> 系统启动时候载入的文件系统不能卸载.启动后载入的可以 umount </I><BR>∶<I> 启动后载入的系统只能 mount 到 /mnt/ </I><BR>∶<I> 4. 安全的进程保护 </I><BR>∶<I> 启动后载入的进程( 其父为 1 ) 不能被杀. </I><BR>∶<I> 5. 安全的模块载入和载出 </I><BR>∶<I> 只能由/sbin/insmod 载入modules. </I><BR>∶<I> 只能载入 /lib/modules 下的 modules </I><BR>∶<I> 系统启动时载入的 modules 不能 rmmod </I><BR>∶<I> 6. 更好的 log 信息. </I><BR>∶<I> 7 . 更多的优点有待你的挖掘 :-)) </I><BR> <BR> <BR>-- <BR>看着她笑,他忽然觉得她好寂寞好寂寞。 <BR>她静静的看了他半天,才柔柔慢慢的:「 你好像已经找到了。」 <BR> <BR>※ 来源:·BBS 水木清华站 bbs.net.tsinghua.edu.cn·[FROM: 202.112.45.46] <BR><CENTER><H1>BBS水木清华站∶精华区</H1></CENTER></BODY></HTML>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -