8
Firewall
The firewall component is a stateful packet filtering firewall which is based
on Netfilter and Iptables. It protects computers against unauthorized
connection attempts. You can use predefined security profiles which are
tailored for common use cases to select the traffic you want to allow and
deny.
Protection Against Unauthorized System Modifications
If an attacker gains a shell access to the system and tries to add a user
account to login to the system later, Host Intrusion Prevention System
(HIPS) detects modified system files and alerts the administrator.
Protection Against Userspace Rootkits
If an attacker has gained an access to the system and tries to install a
userspace rootkit by replacing various system utilities, HIPS detects
modified system files and alerts the administrator.
Protection Against Kernel Rootkits
If an attacker has gained an access to the system and tries to install a
kernel rootkit by loading a kernel module for example through
/sbin/
insmod
or
/sbin/modprobe
, HIPS detects the attempt, prevents the
unknown kernel module from loading and alerts the administrator.
If an attacker has gained an access to the system and tries to install a
kernel rootkit by modifying the running kernel directly via
/dev/kmem
,
HIPS detects the attempt, prevents write attempts and alerts the
administrator.
Summary of Contents for ANTI-VIRUS LINUX CLIENT SECURITY -
Page 1: ...F Secure Anti Virus Linux Server Security Administrator s Guide...
Page 36: ...34 5 USER INTERFACE BASIC MODE Summary 35 Common Tasks 36...
Page 88: ...86 C Riskware Types Riskware Categories and Platforms 87...
Page 91: ...CHAPTERC 89 Riskware Types...
Page 104: ...102 F Man Pages fsav 103 fsavd 137 dbupdate 155 fsfwc 159 fsic 162...
Page 160: ...158 SEE ALSO fsav 1 and fsavd 8 For more information see F Secure home page...
Page 173: ...171 G APPENDIX Config Files fsaua_config 172 fssp conf 177...
Page 206: ...204...
Page 207: ......
Page 208: ...www f secure com...