Re: New rules for su root attempts

Steve Grubb <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
On Wednesday 23 July 2008 11:25:57 Sebastien Tricaud wrote:
> I'd do a generic Authentication classification.text instead.

It would be nice to have definitions with whatever classification we come up 
with. I don't know what a System user is vs Local user. What about service 
users? (gmail, yahoo mail, facebook, etc).


> Bellow the attack classification Pierre and I designed:
>     Authentication
>          Local user
>          System user
>          Admin user
>          Other

What about authorization? You may be authenticated so that the machine knows 
who you are, but then you are not authorized on that service or during that 
time or from a certain location. The what about times when people hit DAC 
denials like opening the password file for writing? Then there are MAC 
denials like SE Linux. I think these fall under some broad category of 
authorization.

>     Probe

Active or passive?

>          Protocol

service?

>          Scan
>          Sniff
>          Users

What about brute forcing passwords?

>          Other

And probing machine names via DNS? Zone transfers?

>     Corruption
>          File
>          Application
>          Other

Kernel? Filesystem?

But corruption is only one kind of thing a malicious user can do. What about 
install a root kit? install a backdoor? install broken ssh? Alter accounts? 
Install keystroke logger? Or access of company confidential docs?

>     Availability (Denial of Service)
>          Resource consumption
>          User account locking
>          Application crash
>          Other

What about data theft? Getting into the system, privilege escalation, user 
initiated like downloading trojan or malicious document, or virus in the 
email or IRC?

There's a whole host of problems that need classifying. The wiki is probably 
the best place for this.

-Steve
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.