60 | F-Secure Linux Security | Using the Product
Baseline
When the Software Installation Mode is enabled, any process can load any kernel modules
regardless whether they are in the baseline or not and any process can change any files in the
baseline, whether those files are protected or not. The real-time scanning is still enabled and it
alerts of any malware found during the installation.
When leaving the Software Installation Mode, the product updates the known files list with new
files and generates the new baseline. If the integrity checking and the rootkit protection features
have been enabled, they are turned back on after the new baseline is generated.
Important: If you install software without the Software Installation Mode when Integrity
Checking monitors updated files, you may be unable to install or use the new software. For
example, Integrity Checking may prevent a kernel update from booting properly as new
drivers are not in the baseline.
Turning on the Software Installation Mode
Turn on the Software Installation Mode when you want to update or modify protected files.
To access the Software Installation Mode, follow these instructions.
1. Open the Web User Interface.
2. Go to
I want to...
page.
3. Click
Install
software.
The Software Installation Mode wizard opens.
The Software Installation Mode wizard guides you through the software installation and updates
the baseline with new software that you install on your system.
You can also use fsims command line tool to use the Software Installation Mode from the
shell.
Integrity Checking is set up by creating a baseline of the system files that you want to protect.
A default set of system files is added to the Known Files List during the installation. By default,
Kernel Module Verification is enabled during the installation and the baseline is generated from
the Known Files List. If you do not enable the Kernel Module Verification during the installation,
you have to generate the baseline manually before Integrity Checking is enabled.
All files that are added to the baseline during the installation are set to
mode.
Allow
and
Alert
protection
Need help?
Do you have a question about the LINUX SECURITY and is the answer not in the manual?