Re: New sensor for Linux deployments

Steve Grubb <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
On Monday 21 January 2008 12:54:31 Steve Grubb wrote:
> I just wanted to drop a line to mention that I've got a new sensor working
> for prelude. This is based on the linux audit system.
>
> The linux audit system, by design, has its hands on nearly all security
> related events. (It does not have iptables events.) The linux audit system
> has a realtime event interface where plugins can be added to analyze events
> as they occur, relay them, or reformat them.

Hi,

i just wanted to update everyone on my progress here. I've incorporated 
feedback from the devel list. I think Yoann has helped guide it to something 
that is more useful for people. The new audit package is available here: 

http://people.redhat.com/sgrubb/audit/

I added 4 new detections since the last email about it. it can now report on 
open/close of promiscuous sockets, changes to SE Linux policy enforcement, 
logins from forbidden locations, and login at forbidden times.

Since the name of the sensor changed, you will have to re-register it with 
prelude-manager. I think the name will be stable from here out. The new name 
is simply auditd. I put some instructions in the audisp-prelude man page.

The latest audit package was built for rawhide and Fedora 8 testing repo 
tonight. Again feedback, comments, or suggestions are welcome.

Thanks,
-Steve
_______________________________________________
Prelude-user site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.