1.0INTRODUCTION
1.1Product Identification
Product Name:
Product Number:
Product Version/Release: 3.1
1.2 Purpose of Document
This document provides basic sizing and tuning guidelines for
1.2 Intended Audience
The data provided in this document is intended to help customers effectively size and tune their systems running HIDS and to help the HP field force effectively size and tune customer configurations for deployment of HIDS.
1.3 Glossary
The following are definitions and acronyms used within this document.
Definitions
•Agent - The HIDS sensor that detects intrusions.
•Event - Any piece of information that is being analyzed by HIDS for intrusions. For example, system call audit records and login records are all delivered to HIDS as events.
•Surveillance Group – A collection of one or more template instances where each instance is of a unique template type.
•Surveillance Schedule – A collection of one or more surveillance groups where each group has its own set of template instances.
•Template or Circuit – Intrusion detection logic that analyzes events. Detects the use of basic attack “building blocks” or patterns.
•Template Instance – An instance of a template. For example, there can be several instances of the Modification of Files/Directories template, each of which monitors for the modification of different critical files or directories.
•Template Type – Specifies which template logic a template instance implements (e.g., Modification of Files/Directories).
•Template Properties – Configuration {name,value} tuples that are used to parameterize a template instance and change a template instance’s behavior at run time. Two template instances of the same template type have the same property names but with potentially different property values. If properties are modified for a surveillance schedule that is running, the schedule must be restarted for the new property values to take effect.
Acronyms
•CPU Central Processing Unit
•HIDS Host Intrusion Detection System – Refers to the
•
•IDDS Intrusion Detection Data Source - A kernel auditing subsystem on 11.11 and 11.23 specifically designed to provide a source of rich,
HP Company Internal | Page 4 of 20 |