Re: New rules for su root attempts
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1216824370.6943.60.camel@arwen> |
Le mercredi 23 juillet 2008 à 08:06 -0400, Steve Grubb a écrit : > On Wednesday 23 July 2008 07:06:13 Yoann Vandoorselaere wrote: > > > I've found that performing 'su - root' task generates no events from > > > prelude-lml sensor on FreeBSD systems. So I added two rules for > > > successfull and non-successfull attempts. I'm not sure what *.rules > > > should be updated (pam.rules or other), so I placed them into su.rules > > > file. > > > > Before including the rules in Prelude-LML, I'd suggest making the > > following modification: > > > > - Use the same classification as PAM (ie: User Authentication). > > Well, su actually has 2 operations, user authentication and change of > credentials that may include new rights via ancilliary groups and of course > capabilities if root. It is possible to have the correct password, but yet be > denied by pam. > > So it would seem to me that you would want any failure in the password to be > logged as an auth failure, but you would want anything else to be recorded as > a change in credentials. Currently, a lot of alert generated use word to indicate successful/failed completion within classification.text. We are in the process of normalizing all classification in order to make it easier for the Correlation agent to work with a set of alert. This is the reason classification.text should not, when possible indicate completion value: impact.completion is preferred for this purpose. I agree through that the current classification is discussable, and might not fit in specific PAM case. We ideally should open a wiki page to create a set of generic classification.text that can be used by any products (hint: contribution in this area are more than welcome): do you have any idea that would better fit for this event? > > - Match on any user (not only root). > > root is the one called out for in many security targets because its a granting > of capabilities. One might target a random user with higher credentials in order to have more access on the machine, this is why we try to match for any user change. -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel