HP-UX System Administrator's Guide: Security Management HP-UX 11i v3 (B3921-90020, September 2010)

Table Of Contents
Provides continuous protection against both existing attack scenarios and unknown
scenarios unlike other intrusion detection systems. It detects intrusions by using
detection templates. Detection templates are the building blocks used to identify
the basic types of unauthorized system activity or security attacks frequently found
on enterprise networks.
Provides notification in the event of suspicious activity that might precede an
attack. By contrast, other intrusion detection systems rely entirely on an
operator-instigated analysis of the system log files. Typically the operator analyses
the system log files at the end of the day. This delay in the analysis of the attack
provides considerable time to damage the system.
For more information, see the HP-UX HIDS documentation:
http://www.hp.com/go/hpux-security-docs
Click HP-UX Host Intrusion Detection System Software.
B.6 HP-UX IPFilter
HP-UX IPFilter is a system firewall that filters IP packets to control packet flow in or
out of a machine. It works as a security defense by cutting down on the number of
exposure points on a machine.
For more information, see the HP-UX IPFilter documentation:
http://www.hp.com/go/hpux-security-docs
Click HP-UX IPFilter Software.
B.7 HP-UX IPSec
HP-UX IPSec provides an infrastructure to allow secure communications (authentication,
integrity, confidentiality) over IP-based networks between systems and devices that
implement the IPsec protocol suite.
For more information, see the HP-UX IPSec documentation:
http://www.hp.com/go/hpux-security-docs
Click HP-UX IPSec Software.
B.8 HP-UX LDAP-UX Integration
With an LDAP-enabled directory server, LDAP-UX Integration provides your HP-UX
system centralized user, group, and system management, along with centralized
authentication and access control. LDAP-UX supports standard LDAP directory servers
as well as Windows Active Directory, for which HP-UX can use the same management
groups and policies as in a Windows domain. In addition, users from multiple domains
can authenticate to HP-UX. To simplify authentication and access control, LDAP-UX
can defer to centralized password and account policies as well as define highly
customizable access control policies for HP-UX services.
LDAP-UX includes numerous integration features: centralized configuration, flexible
group management that includes support for standard LDAP groups or dynamic
B.6 HP-UX IPFilter 195