HP-UX Host Intrusion Detection System Version 4.2 Release Notes
1 Announcement
The HP-UX Host Intrusion Detection System Version 4.2 Release Notes describes major new features,
enhancements, fixes, limitations, and known issues for Host Intrusion Detection System (HIDS)
Version 4.2.
What is HP-UX HIDS
HP-UX HIDS is a host-based HP-UX security product for HP computers running HP-UX 11i.
HP-UX HIDS enables security administrators to proactively monitor, detect, and respond to
attacks targeted at specific hosts. Many types of attacks can bypass network-based detection
systems. HP-UX HIDS monitors these bypassed attacks and complements the existing
network-based security mechanisms, bolstering enterprise security.
HP-UX HIDS seeks patterns that might suggest security breaches or misuse by examining
information about system activity from a variety of data sources. It detects illicit activities that
include attempting to break into or disrupt the system, modifying system files and directories,
or attempting to spread a virus. When HP-UX HIDS detects an intrusion attempt, it issues an
alert to the administrative interface, where users can immediately investigate the situation, and
take necessary action against the intrusion. In addition, users can customize a local response to
an alert as described in Appendix B, Response Programs in the Host Intrusion Detection System
Administrator’s Guide.
HP-UX HIDS is particularly useful for enterprise environments in which centralized management
tools control networks of heterogeneous systems. These environments include Web servers,
transaction processors, application servers, and database systems.
Compatibility with Previous Versions
HP-UX HIDS version 4.2 software is backward compatible with version 4.1, version 4.0, and
version 3.1. However, schedules created with 3.1 and 4.0 versions of HIDS must be migrated to
HIDS version 4.2. Schedules created with 4.1 version of HIDS do not need to be migrated.
However, in order for a 4.1 schedule to contain the new 4.2 schedule global properties, the
migrator tool must be run on the v4.1 schedule or the 4.2 GUI must be started to load and save
the v4.1 schedule or the schedule text file must be directly edited to add the new global variables.
For more information about migration, see “Migrating Schedules from Older Versions of HIDS”
(page 21)
HP recommends that users upgrade all systems to HIDS version 4.2.
NOTE: HP-UX HIDS v4.2 is not backward compatible with HIDS v1.0 and HIDS v2.0, HIDS
v2.1, and HIDS v2.2 (collectively referred to as 2.x). HIDS v1.0 and HIDS v2.x are obsolete. HIDS
version 4.2 schedules created on the administration system with Log File Monitoring feature
enabled cannot be activated on HP-UX HIDS 4.1 agents.
Compatibility with Other Products
HP-UX HIDS is not compatible with all HP software products; see Table 1-1 for the list of products
that are supported. Do not run HP-UX HIDS on systems that are running unsupported products
(or vice versa).
Table 1-1 HP-UX HIDS Product Compatibility
Supported?Product
YesHP-UX 11i v3
YesHP-UX 11i v2
What is HP-UX HIDS 7