Paketname | stealth |
Beschreibung | A stealthy File Integrity Checker |
Archiv/Repository | Offizielles Debian Archiv squeeze (main) |
Version | 1.47.4-1 |
Sektion | admin |
Priorität | optional |
Installierte Größe | 296 Byte |
Hängt ab von | libbobcat2 (>= 2.03.00), libc6 (>= 2.3.6-6~), libgcc1 (>= 1:4.1.1), libstdc++6 (>= 4.3) |
Empfohlene Pakete | |
Paketbetreuer | Frank B. Brokken |
Quelle | |
Paketgröße | 95172 Byte |
Prüfsumme MD5 | e9453c9c9f64d11c9e4eeab84e208d6e |
Prüfsumme SHA1 | 039ff58f5ba3fc3f9ccdf2e33f216280f9d06a72 |
Prüfsumme SHA256 | aa6a764de2c64f1d8dc89392de9ce592d34925efd16daa50244d85e58a8f447f |
Link zum Herunterladen | stealth_1.47.4-1_i386.deb |
Ausführliche Beschreibung | The STEALTH program performs File Integrity Checks on (remote) clients. It
differs from other File Integrity Checkers by not requiring baseline
integrity data to be kept on either write-only media or in the client's file
system. In fact, client's will contain hardly any indication at all that they
are being monitored, thus improving the stealthiness of the integrity scans.
.
STEALTH uses standard available software to perform file integrity checks
(like find(1) and md5sum(1)). Using individualized policy files, it is highly
adaptable to the specific requirements of its clients.
.
In production environments STEALTH should be run from an isolated computer
(called the `STEALTH monitor'). In optimal configurations the STEALTH
monitor should be a computer not accepting incoming connections. The account
used to connect to its clients does not have to be `root': usually
read-access to the client's file system is enough to perform a full integrity
check. Instead of using `root' a more restrictive administrative or
ordinary account might offer all requirements for the desired integrity
check.
.
STEALTH itself must communicate with the computers it should monitor. It is
essential that this communication is secure, and STEALTH configurations will
therefore normally specify SSH as the command-shell to use to connect to its
clients. STEALTH may be configured so as to use but one SSH connection per
client, even if integrity scans are to be performed repeatedly. Apart from
this, the STEALTH monitor might be allowed to send e-mail to remote clients
system's maintainers.
.
STEALTH-runs itself may start randomly within specified intervals. The
resulting unpredicability of STEALTH-runs further increases STEALTH's
stealthiness.
.
STEALTH's acronym is expanded to `Ssh-based Trust Enforcement Acquired
through a Locally Trusted Host': the client's trust is enforced, the locally
trusted host is the STEALTH monitor.
|