1.1 PRODUCT IDENTIFICATION...............................................................................................
4
1.2 PURPOSE OF DOCUMENT ..................................................................................................
1.2 INTENDED AUDIENCE.......................................................................................................
1.3 GLOSSARY .......................................................................................................................
2.0 OVERVIEW......................................................................................................................
5
2.1 PRODUCT OVERVIEW .......................................................................................................
2.2 HP-UX HIDS DEPLOYMENTS .........................................................................................
2.3 SIZING AND TUNING OVERVIEW ......................................................................................
3.0 SIZING AND TUNING RECOMMENDATIONS........................................................
6
3.1 SIZING GUIDELINES .........................................................................................................
3.1.1 Single vs. Multi-Processor .......................................................................................
3.1.2 Number of CPUs ......................................................................................................
3.1.3 Memory ....................................................................................................................
3.1.4 Disk Capacity...........................................................................................................
7
3.2 TUNING CONSIDERATIONS ...............................................................................................
3.2.1 Product Tuning ........................................................................................................
3.2.1.1 Tuning the Surveillance Schedules...................................................................
3.2.1.1.1 Background................................................................................................
3.2.1.1.2 Avoid duplicate copies of a template.........................................................
3.2.1.1.3 Avoid duplicate groups with overlapping functionality ............................
3.2.1.1.4 Race Condition Template ..........................................................................
8
3.2.1.2 Tuning Process Priority.....................................................................................
3.2.1.3 Tuning the HIDS System Manager (GUI)........................................................
3.2.2 Kernel Tuning ..........................................................................................................
3.2.2.1 Tuning the Kernel Audit System (IDDS) .........................................................
3.2.2.1.1 System performance over security.............................................................
9
3.2.2.1.2 Security over system performance.............................................................
3.2.2.1.3 How to change from non-blocking to blocking mode ...............................
3.2.2.2 Kernel Tunables................................................................................................
3.2.2.2.1 enable_idds .........................................................................................
3.2.2.2.2 max_thread_proc................................................................................
3.2.2.2.3 tcp_conn_request_max....................................................................
3.2.2.2.4 secure_sid_scripts ........................................................................
3.2.2.2.5 executable_stack ...........................................................................
10
3.2.2.2.6 maxdsiz.................................................................................................
3.2.2.3 Swap................................................................................................................
11
12
CPU Consumption on PA Processors ...........................................................................
13
CPU Consumption on Itanium Processors...................................................................
15
17
Memory Consumption on PA Processors .....................................................................
Memory Consumption on Itanium Processors .............................................................
19
HP Company Internal
Page 3 of 20