Re: New sensor for Linux deployments
Steve Grubb <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
On Monday 21 January 2008 12:54:31 Steve Grubb wrote: > I just wanted to drop a line to mention that I've got a new sensor working > for prelude. This is based on the linux audit system. > > The linux audit system, by design, has its hands on nearly all security > related events. (It does not have iptables events.) The linux audit system > has a realtime event interface where plugins can be added to analyze events > as they occur, relay them, or reformat them. Hi, i just wanted to update everyone on my progress here. I've incorporated feedback from the devel list. I think Yoann has helped guide it to something that is more useful for people. The new audit package is available here: http://people.redhat.com/sgrubb/audit/ I added 4 new detections since the last email about it. it can now report on open/close of promiscuous sockets, changes to SE Linux policy enforcement, logins from forbidden locations, and login at forbidden times. Since the name of the sensor changed, you will have to re-register it with prelude-manager. I think the name will be stable from here out. The new name is simply auditd. I put some instructions in the audisp-prelude man page. The latest audit package was built for rawhide and Fedora 8 testing repo tonight. Again feedback, comments, or suggestions are welcome. Thanks, -Steve _______________________________________________ Prelude-user site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-user