« Icon | Main | Freestyle in three minutes »

Professional paranoid

There are so many places I can go with that title.

In computer cracking, there is a little bundle of nasty known as a rootkit. Essentially, it replaces a whole series of operating system components so the sysadmin (me) can't see what varieties of mischief are being performed on their system.

Since this is an arms race, there is a utility named chkrootkit which checks for the fingerprints of a rootkit, essentially telling the sysadmin, "You are now on thin ice, get this box off the network." The TLA (Three Letter Acronym) is IDS, or Intrusion Detection System (though there are more thorough IDSes in the world, like tripwire and fcheck.)

Now, various versions of chkrootkit vary in how well they detect various rootkits. And, because I'm responsible for keeping our system(s) secure, I am professionally paranoid.

So cron (the scheduling daemon) is running five different versions of chkrootkit over the course of each day, and emailing me the results. This is the rough equivalent of giving an employee a polygraph every five hours, forever. (Except the employee works as much as eighty-six days without so much as a coffee break, so the metaphor is sketchy.)

Post a comment