Re: New rules for su root attempts

"G Ramon Gomez" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <622FD37285F1584386F5F83D9D233C9C02CC27EC@SMF-ENTXM-001.sac.ragingwire.net>
Steve (and all),
What you seem to be asking for is more specific information in classification.text.  That's a reasonable request, considering that classification.text is what folks see first in the front-end.  HOWEVER...
A few years ago classification.text was abstracted for a reason.  You can see it in pcre.rules (from LML) in this comment:

# - If a similar rule exists in another ruleset (same function, different
#   software), use the classification().text from the other rule.

So...why?
Well, it's due to the correlation engine.  We needed a single field (doesn't matter which field) that has event description data that is specific enough to have a meaning, while being abstract enough to match events that are similar from other devices.  We considered an additional_data field, but the problem was that some devices (in particular Snort) don't provide this data natively, and for the best compatibility, we should use a standard IDMEF field.
Classification.text became that field because it's an "overview" field anyway, and there are other fields that can provide additional data and description to the extended event view.
Having the field abstracted in this way allows the correlation engine to take data from multiple devices and understand that it could be related.  It allows us to find things like a "low and slow" scan against multiple devices even though in one case a wireless device is having a bunch of association attempts, while arpwatch is complaining about MAC flip-flops.
Does this help?

- Ramon

-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of Steve Grubb
Sent: Wednesday, July 23, 2008 11:07 AM
To: Sebastien Tricaud
Cc: Yoann Vandoorselaere; [email protected]
Subject: Re: [prelude-devel] New rules for su root attempts

On Wednesday 23 July 2008 11:25:57 Sebastien Tricaud wrote:
> I'd do a generic Authentication classification.text instead.

It would be nice to have definitions with whatever classification we come up with. I don't know what a System user is vs Local user. What about service users? (gmail, yahoo mail, facebook, etc).


> Bellow the attack classification Pierre and I designed:
>     Authentication
>          Local user
>          System user
>          Admin user
>          Other

What about authorization? You may be authenticated so that the machine knows who you are, but then you are not authorized on that service or during that time or from a certain location. The what about times when people hit DAC denials like opening the password file for writing? Then there are MAC denials like SE Linux. I think these fall under some broad category of authorization.

>     Probe

Active or passive?

>          Protocol

service?

>          Scan
>          Sniff
>          Users

What about brute forcing passwords?

>          Other

And probing machine names via DNS? Zone transfers?

>     Corruption
>          File
>          Application
>          Other

Kernel? Filesystem?

But corruption is only one kind of thing a malicious user can do. What about install a root kit? install a backdoor? install broken ssh? Alter accounts? 
Install keystroke logger? Or access of company confidential docs?

>     Availability (Denial of Service)
>          Resource consumption
>          User account locking
>          Application crash
>          Other

What about data theft? Getting into the system, privilege escalation, user initiated like downloading trojan or malicious document, or virus in the email or IRC?

There's a whole host of problems that need classifying. The wiki is probably the best place for this.

-Steve
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.