|
ABSTRACT:
GFI LANguard S.I.M. integrates with GFI LANguard Security Event Log Monitor (S.E.L.M.), GFI's host-based intrusion detection system designed to monitor Windows-based networks for security breaches in real time. GFI LANguard S.I.M. works by generating a checksum for the important files. This is done with MD5, an industry standard one-way hash algorithm developed by one of the world's greatest cryptographers (Ronald Rivest, the 'R' in 'RSA'). The resulting checksum is then stored in a GFI LANguard S.I.M. database. At predetermined intervals a new checksum is generated and compared to the one stored in the database. If it differs, this means that the file has changed and is therefore suspect. An email alert is immediately sent to an administrator. |
| |
 |