HP-UX 11i Version 2 June 2007 Release Notes

Security
HP-UX Host Intrusion Detection System
Chapter 8
179
Impact
These represent additional items that Bastille will be able to lock down, additional
usability improvements, and a new ability for Bastille to ensure that each cluster node
has a consistent set of security settings.
Compatibility
There are no differences between the Itanium-based and PA-RISC implementation
(they are the same). Some products depend on services, system settings, or network ports
that Bastille secures. In those cases, products that depend on out-of-box settings that
Bastille may change, document their dependency. Where practical, Bastille also
documents these dependencies.
Performance
Though Bastille does not directly affect performance, its configuration of IPFilter
settings (host-based firewall), will cause a slight network performance decrease.
Documentation
Information can be found in the following documents:
bastille (1M) manpage (add /opt/sec_mgmt/share/man/ to MANPATH)
Bastille User’s Guide, delivered in
/opt/sec_mgmt/bastille/docs/user_guide.txt
HP-UX Bastille Web site at http://www.hp.com/go/bastille
HP-UX 11i v2 Installation and Update Guide, available online at
http://www.docs.hp.com/en/oshpux11iv2.html
“Install-Time Security” on page 184
Support is also offered through HP's IT Resource Center’s HP-UX Security Forum at
http://forums1.itrc.hp.com/service/forums/parseCurl.do?CURL=%2Fcm%2FCategoryHome%
2F1%2C%2C155%2C00.html&admit=-682735245+1157685896487+28353475
Obsolescence
Not applicable.
HP-UX Host Intrusion Detection System
HP-UX Host Intrusion Detection System (HIDS) Release 4.1 is a host-based HP-UX
security product for HP computers running HP-UX 11i. HP-UX HIDS Release 4.1
enables security administrators to proactively monitor, detect, and respond to attacks