From: Pedro Rosa <Pedro.Rosa@ksu.ru>
Cc: Stephen Smalley <sds@tislabs.com>,
Jeff Largent <jlargent@imagelinks.com>,
selinux <selinux@tycho.nsa.gov>
Subject: Re: lids
Date: Wed, 21 Mar 2001 03:37:20 +0300 [thread overview]
Message-ID: <3AB7F7C0.4080506@ksu.ru> (raw)
In-Reply-To: Pine.LNX.4.30.0103201734350.549-100000@biocserver.BIOC.CWRU.Edu
Jose Nazario wrote:
> On Wed, 21 Mar 2001, Pedro Rosa wrote:
>
>> Sorry but LIDS stands for Linux Intrusion Detection System. Its main
>> purpose has nothing to do with what SELinux deals with. I don't know
>> too much about the inners of LIDS but I know that it is an evolution
>> of some ideas based on NIDS (Network Intrusion Detection System).
>
>
> the name LIDS is a misnomer. as someone who works a lot with IDS stuff, it
> pisses me off, too, that such a fundamental mistake was made in the
> naming.
>
> http://www.lids.org/about.html
Well I just decided to take a walk through this LIDS world... Yes, you
are right about the name... However this tool is far from being
equivalent to SELinux.
ACLs are one of its main components but not the main one.
First LIDS present a series of switch options. It looks like that you
can turn on or off this stuff in a very flexible and dynamic manner.
Second LIDS presents some features with a very non-traditional taste.
For example, it tries to hang-up the programs that violate the
restrictions. Besides the way programs depend on ACLs is not seen
exactly in the same view of SELinux. Here things look more as walking on
a minefield rather than impose an administrative order in work.
Third LIDS has tools that put it much more near a NIDS. For example it
registers net scannings. But not only, it also tries to protect the
system from DoS attacks based on this capability. And it tries to be
simple and concise in reporting repeating events.
Fourth it has a remote reporting system that sounds much like those seen
on some monitoring systems.
I would consider that LIDS is more a tool for those users who occur to
be in a untrusted environment or are forced to go regularly through
such. On the contrary, SELinux sounds much more like a tool that
guarantees the existence of a trusted environment. Besides I think that
there is a big difference on both. On SELinux we have MACs, which seem
controlled from a central point. On LIDS we just have a strict set of
controls that are not controlled from any center. In fact LIDS looks
quite autonomous in terms of setup.
Frankly I can't state anything good or bad about these two systems. They
have clearly two different purposes. They are only similar on particular
points but we cannot state any strongnesses or weaknesses here. In fact
a central administration could be useless or even damaging to what LIDS
pretends to answer. Imagine taking a trip to a foreign country with your
notebook full of valuable data. On the other way, an administrative
autonomy on SELinux would only rise the consume of coffee and cigarettes
among sysadmins.
Ektanoor
>
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2001-03-21 0:41 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-03-19 19:44 lids Jeff Largent
2001-03-20 14:22 ` lids Stephen Smalley
2001-03-20 21:29 ` lids Pedro Rosa
2001-03-20 22:20 ` lids Stephen Smalley
2001-03-20 22:41 ` lids Jose Nazario
2001-03-21 0:37 ` Pedro Rosa [this message]
2001-03-21 0:31 ` lids Tracy R Reed
2001-03-21 0:56 ` lids Pedro Rosa
2001-03-21 14:20 ` lids Stephen Smalley
2001-03-21 16:46 ` lids Pedro Rosa
2001-03-22 11:09 ` [selinux] lids Magosányi Árpád
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3AB7F7C0.4080506@ksu.ru \
--to=pedro.rosa@ksu.ru \
--cc=jlargent@imagelinks.com \
--cc=sds@tislabs.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.