- This topic has 3 replies, 2 voices, and was last updated Dec 21-9:15 pm by DaveW.
Viewing 4 posts - 1 through 4 (of 4 total)
Viewing 4 posts - 1 through 4 (of 4 total)
- You must be logged in to reply to this topic.
Forum for users of antiX Linux. Mean and Lean and Proudly anti-fascist.
Forum › Forums › New users › New Users and General Questions › Re: AIDE Advanced Intrusion Detection Environment
What is your experience with AIDE (or similar security enhancements) to keep an eye out for malware, etc.?
(I’m currently using Antix17, and running Firefox and Thunderbird in Firejail with apparmor.)
IMO, aide (and “tiger” and “snort”) provide little benefit (for any desktop system that is not configured to perform unattended upgrades) and they present a HUGE time sink (eternally chasing down false positives).
If any “files of interest” are changed underfoot, I want to be informed RIGHT NOW, immdeiately, via popup notification (or klaxon sound) ~~ not tomorrow, via email, after the cron-ned aide job has run.
Which exact set of files and / or directories should be “files of interest” on my (your) system?
https://sources.debian.org/src/aide/0.16.1-1/debian/aide.conf.d/
debian’s as-shipped default configuration:
https://sources.debian.org/src/aide/0.16.1-1/debian/default/aide/
^— By skimming through these, a sysadmin can gauge which files and directories the aide author(s) and debian’s package maintainer(s) consider to be interesting. Also, inspecting their chosen default exclusion items can be enlightening… and, by golly, we should pity the well-intentioned fools managing public-facing servers who blindly accept (do not customize) the defaults.
Skidoo,
Your quick assessment is much appreciated. I think you saved me a lot of time.
I agree it would be best to have an instantaneous loud alarm when something goes amuck… your klaxon, for example.
On the other hand, due to the likelihood of many false alarms, it might be necessary to remove my hearing aids.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |