Re: New rules for su root attempts
Steve Grubb <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wednesday 23 July 2008 11:25:57 Sebastien Tricaud wrote: > I'd do a generic Authentication classification.text instead. It would be nice to have definitions with whatever classification we come up with. I don't know what a System user is vs Local user. What about service users? (gmail, yahoo mail, facebook, etc). > Bellow the attack classification Pierre and I designed: > Authentication > Local user > System user > Admin user > Other What about authorization? You may be authenticated so that the machine knows who you are, but then you are not authorized on that service or during that time or from a certain location. The what about times when people hit DAC denials like opening the password file for writing? Then there are MAC denials like SE Linux. I think these fall under some broad category of authorization. > Probe Active or passive? > Protocol service? > Scan > Sniff > Users What about brute forcing passwords? > Other And probing machine names via DNS? Zone transfers? > Corruption > File > Application > Other Kernel? Filesystem? But corruption is only one kind of thing a malicious user can do. What about install a root kit? install a backdoor? install broken ssh? Alter accounts? Install keystroke logger? Or access of company confidential docs? > Availability (Denial of Service) > Resource consumption > User account locking > Application crash > Other What about data theft? Getting into the system, privilege escalation, user initiated like downloading trojan or malicious document, or virus in the email or IRC? There's a whole host of problems that need classifying. The wiki is probably the best place for this. -Steve _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel