Integrit – File Verification System

Use Netsparker


Integrit is a file verification system, a simple yet secure alternative to products like tripwire. It has a small memory footprint, uses up-to-date cryptographic algorithms, and has features that make sense (like including the MD5 checksum of newly generated databases in the report).

Integrit - File Verification System

The Integrit system detects intrusion by detecting when trusted files have been altered.

By creating an Integrit database (update mode) that is a snapshot of a host system in a known state, the host’s files can later be verified as unaltered by running integrit in check mode to compare current state to the recorded known state. Integrit can do a check and an update simultaneously.

Other options are:

AIDE – Advanced Intrusion Detection Environment
Tiger – Unix Security Audit & Intrusion Detection Tool
Samhain v.2.5.9c – Open Source Host-Based Intrusion Detection System (HIDS)
OSSEC HIDS – Open Source Host-based Intrusion System

Usage

Using a product like Integrit for intrusion detection is a continuous process, involving a sequence something like the following:

  1. Generate a new current-state database while checking against an old known-state database that has been protected from modification (This step can be done unattended, since the report that integrit generates at runtime includes the MD5 checksum of the newly-generated current-state database. The output should be directed to a remote host, e.g., via a trusted sendmail binary.) *
  2. Read the report, possibly using UN*X or XML tools to massage it into a form to your liking (There is an example GUI viewer for integrit’s XML output in the examples directory of the distribution.)
  3. If the report looks fine, copy the new database to a secure server for export via read-only NFS, or a secure medium that can be made read-only.
  4. Verify that the current md5sum of the database you just copied over matches the MD5 checksum in the report. (This shows that no one has tampered with the database since the report and the new database were generated.)
  5. Everything’s OK, so the new database will be the known-state database the next time you repeat this process.

* You may use a script to renice the Integrit process and possibly do a sequence of runs, each with a different configuration file.

Output

The human-readable format is intended for quick scanning on a viewer with a large number of columns (like an xterm with maximized width).

Other popular file integrity verification systems split the information between a list of files that have changed at the top of the report and a more detailed section showing the nature of the changes at the bottom of the report. Instead, integrit provides all the information for each file as it learns it.

Besides saving on runtime memory usage, the big advantage of this approach is that the person reading the output never has to skip to the end of the report to learn the exact nature of a change.

You can download integrit here:

integrit-4.1.tar.gz

Or read more here.

Posted in: Countermeasures, Security Software


Latest Posts:


Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.


Comments are closed.