Host Intrusion Prevention
Desktops Laptops
Many companies consider servers to be their most important assets, but there is just as much (if not more) sensitive information on the desktops and laptops that the user community uses on a daily basis. In some cases, users of desktops and laptops have more freedom to install software to decide what information is processed on them, and where they can be placed to allow the business to operate. By their nature, desktops and laptops are also more vulnerable to attacks because of this...
CSACTL for Solaris Linux
Solaris and Linux use a command-line interface (CLI) to manage the local agent. Although Linux has a GUI, more options are available from the CLI and it gives you access to just as much information. In fact, CSACTL provides a way to poll from the command line, a feature absent in Windows. The default path to CSACTL is opt CSCOcsa bin. NOTE Remember that when running CSACTL, you might need to prepend . if you do not use An important feature of CSACTL is the ability to generate an event to send...
What Does Training Encompass
Training for CSA takes on a wide range of possible forms depending on your environment. However, here are some examples that apply to most environments Administrators System managers of the Management Center Read the CSA documentation (at least the installation and release notes). Some portion of the administration staff should attend a CSA training class if possible to get professional hands-on training, even if it is a train-the-trainer situation.
Agent Kit Dissection
After you retrieve an Agent Kit, you can install it on the system. The executable file is nothing more than a self-extracting zipped file that contains all the installation components and initial configuration settings required. Double clicking this file starts the installation, which this chapter later discusses. First, you need to open the executable in WinZip to view the files and learn more about what makes up an installer. This allows you to create scripted installers you can use in login...
Agent and Csa Mc Communication
There are various communication paths that must be available between the agents and the CSA MC architecture to allow seamless updates and security event notification. When sending security events from the remote agent to the CSA MC console, the agent uses an SSL- encrypted connection on TCP port 5401. If a connection cannot be made on that port, the agent uses SSL over the standard TCP port 443. As of CSA 4.5, software updates and policy updates from the CSA MC to the agent are no longer sent...
Filtering the Event Log Using Change Filter
When you attempt to specify events to complete a management task, such as tuning or security investigation, it is advantageous to limit the data presented on the screen, so that the administrators can quickly and easily see patterns emerge that allow them to accomplish their goal. The Event Log Change Filter option allows the administrator to filter the Event Log using specified criteria. To view the current filter criteria, look to the top, left corner of the Event Log screen.
Allowing Scripted Uninterrupted Uninstall
When you attempt to run a silent command-line uninstallation, you often run into issues when the currently installed CSA policy queries prompt the user. These queries are typically related to stopping the agent service and running installation programs. You can circumvent these issues through CSA policy implementation and a tool like SysInternals PSEXEC, which allows you to run commands on local and remote systems as another user. To accomplish this, follow a few simple steps to make an...
Acknowledgments
Chad Sullivan I would like thank God for giving me the wonderful family and friend support team he has provided. Thanks to my wife and children for understanding when Daddy needs to write and cannot play. Thanks to my parents and sister for driving me to continue to exceed my own expectations. Thanks to my mother- and father-in-law who help our family more than they may ever know. Thanks to Larry Boggis for joining me on my ride into entrepreneurship. A special thanks to the technical editors...
Quality Assurance Debugging
How does your quality assurance group know if an issue that never happened before or cannot possibly be this application is related to CSA or not They can take a severe route, if your policy allows it, and remove CSA to see if that changes the situation. However, by now you should know that there are alternative methods to most quality assurance and testing issues. The following are suggestions your quality assurance group can use. There are two ways to disable CSA temporarily that do not...
Web Serveri PlanetSolaris
The iPlanet Web Server policy is similar to the IIS module in that it is a combination of a generic Common Web Server Security module and the more specific iPlanet module. Many of the protections provided by this module are the same as the IIS module, except that they use Unix commands and objects instead of those found in Windows. Rules for XSS, SQL command injection, and common log file exploits are present in this module just as in the IIS module. The rules in this module are shown in Figure...





