Linux Intrusion Detection System
LIDS — the Linux Intrusion Detection System — brought Mandatory Access Control to the Linux kernel, protecting files and processes even from the superuser, years before such hardening was mainstream. This site preserves the project's history, releases, and news.
# No one — including root — can touch this: lidsconf -A -o /etc/shadow -j READONLY lidsconf -A -s /usr/sbin/sshd \ -o /etc/shadow -j READ # seal the kernel lidsadm -I
What was LIDS?
From the original project pages.
The problem
In a stock GNU/Linux system of the era, the file system, processes, and system administration were unprotected; the superuser could abuse its rights; and discretionary access control (DAC) was not enough. One compromised daemon running as root meant the whole machine was gone.
The answer
A kernel patch and admin tools implementing a reference monitor and Mandatory Access Control in the kernel itself — an active project with many helpful hackers.
The legacy
Ported to the LSM framework in 2002; voted into insecure.org's top security tools by the Nmap community.
Paving the way
LIDS helped prove that in-kernel mandatory access control was practical for production Linux — the world SELinux and AppArmor later made standard. Its patches (Linux 2.2 through 2.6.34) and tools are preserved here and on GitHub for historical and research use.
Features
As described on the original About page.
File protection
No one, including root, can modify LIDS-protected files. Files can be hidden entirely.
Process protection
Protected processes cannot be killed — even by root — and can be hidden from view.
Fine-grained ACLs
Access control lists over files, processes, and network resources, enforced in the kernel.
Capability control
Uses and extends Linux capabilities to control the whole system, limiting the power of root.
Kernel alerts
Security violations reported straight from the kernel, with an in-kernel port scan detector.
Sandboxing (TDE)
Trusted Domain Enforcement confined daemons like Apache and Samba to their own domains, so a hijacked service couldn't abuse its privileges against the rest of the system.
Project timeline
Milestones from fourteen years of development.
-
1999
Project founded
Huagang Xie starts LIDS, with early support from the Software Research Center at the Institute of Computing Technology, and hosting from Turbolinux China.
-
2000
Recognition
Named "Best of Linux" by Linux.DaveCentral.com; later voted into insecure.org's top security tools list by the Nmap community.
-
2001 – 2002
Two stable branches
Philippe Biondi co-maintains releases across kernel 2.2 (0.x) and 2.4 (1.1.x) while development races ahead on 2.5.
-
2002
LIDS joins the LSM tree
LIDS 2.0 is ported to the Linux Security Modules framework and included in the LSM 2.5 tree — LIDS can now be built as a kernel module.
-
2004 – 2005
TDE sandboxing & worldwide coverage
Trusted Domain Enforcement lands (paper by Yusuf Wilajati Purna). Articles appear on Linux.com, in c't (Netherlands), Network World Japan, and in German and Japanese books.
-
2005 – 2009
The 2.6 era
LIDS 2.2.x tracks the fast-moving 2.6 kernel from 2.6.11 through 2.6.32, with the LIDS-JP community (Omo Kazuki) providing packages and documentation from lids.jp.
-
2010 – 2013
Final years
The site moves hosts, the forum moves to lids.jp, and development winds down as LSM-based systems like SELinux and AppArmor become standard in mainline distributions.
Talks, books & articles
LIDS on stage and in print — the DEF CON 10 talks by the two lead developers, and coverage from the Linux press.
DEF CON 10 — Linux Kernel Security with LIDS
Huagang Xie presents the background, architecture, and use of LIDS —
what attacks it detects and prevents, and how to build a secure Linux
system with it. Las Vegas, August 2002.
Watch on YouTube ↗ ·
Slides (DEF CON archive) ↗
DEF CON 10 — Security at Kernel Level
Philippe Biondi on moving the trust boundary between user space and
kernel space, and enforcing security policy from inside the kernel — with
practical Linux implementations. Las Vegas, August 2002.
Watch on YouTube ↗ ·
Slides (PDF) ↗
Book: Intrusion Detection für Linux-Server
Ralf Spenneberg's German-language book (2003) covers LIDS extensively, together with Tripwire, Snort, and forensics.
Book: Linux Secure Server (Nikkei-BP)
The Japanese "Linux Secure Server" book (2004) includes a chapter explaining LIDS 2.2.0, written by Omo Kazuki of LIDS-JP.
Linux Journal
"Getting Started with the Linux Intrusion Detection System" — a hands-on
introduction to the kernel patch, lidsconf, and lidsadm.
Read the article ↗
Linux.com
"An overview of LIDS" — securing a server by limiting the power of root
with kernel-enforced ACLs.
Read the article ↗
LinuxSecurity.com
"Creating a Secure Linux Environment Using LIDS Technology" — protection,
detection, and response in the Linux kernel.
Read the article ↗
Linux Magazine
"Closing the Lid" (2009) — locking down a system with LIDS in the
2.6-kernel era.
Read the article ↗
TDE: An Introduction
Yusuf Wilajati Purna's 2005 paper introducing Trusted Domain Enforcement — sandboxing trusted applications like Apache and Samba so hijacked privileges can't breach the rest of the system.
In print & encyclopedias
A three-page feature in the Dutch edition of c't (issue 3/2004), a TDE how-to in Network World Japan (June 2005), and the Wikipedia entry ↗.
Final releases
The last published versions for each kernel branch. The recovered LIDS 2.2.3 kernel patches (Linux 2.6.18–2.6.34) and lidstools source are preserved at github.com/hgxie/lids; older copies survive on the Internet Archive.
| Kernel branch | Final LIDS version | Tools |
|---|---|---|
| Linux 2.6.31/32 | lids-2.2.3rc9 | lidstools-2.2.7.8 |
| Linux 2.6.14 (stable) | lids-2.2.2 | lidstools-2.2.7 |
| Linux 2.4.30 | lids-1.2.2 | lidstools-0.5.7 |
| Linux 2.2.22 | lids-0.11.1pre1 | — |
People
LIDS was built by a community.
Huagang Xie
Founder and lead developer, 1999–2013.
Philippe Biondi
Co-developer; maintained the 2.2 and 2.4 kernel branches.
Yusuf Wilajati Purna
Author of the Trusted Domain Enforcement (TDE) sandboxing feature.
Omo Kazuki & LIDS-JP
The Japanese LIDS community — packages, wiki, forum, and the final years of releases at lids.jp.
Early supporters
Prof. Bai Shuo, Bu Dongbo, Christophe Long, Webmotion Inc., and Turbolinux China, who hosted the first lids.org.
…and many more
Contributors, packagers, translators, and bug reporters across the mailing lists and forums.