
system on a critical error, audit makes sure that no process escapes from its control as
it otherwise might if level 1 (
printk
) were chosen.
IMPORTANT: Choosing the Failure Flag
Before using your audit rule set on a live system, make sure that the setup has
been thoroughly evaluated on test systems using the worst case production
workload. It is even more critical that you do this when specifying the
-f 2
flag, because this instructs the kernel to panic (perform an immediate halt
without flushing pending data to disk) if any thresholds are exceeded. Consider
the use of the
-f 2
flag for only the most security-conscious environments.
32.2 Adding Watches on Audit Log
Files and Configuration Files
Adding watches on your audit configuration files and the log files themselves ensures
that you can track any attempt to tamper with the configuration files or detect any at-
tempted accesses to the log files.
NOTE: Creating Directory and File Watches
Creating watches on a directory is not necessarily sufficient if you need events
for file access. Events on directory access are only triggered when the directory's
inode is updated with metadata changes. To trigger events on file access, add
watches for each individual file to monitor.
-w /var/log/audit/
❶
-w /var/log/audit/audit.log
#-w /var/log/audit/audit_log.1
#-w /var/log/audit/audit_log.2
#-w /var/log/audit/audit_log.3
#-w /var/log/audit/audit_log.4
-w /etc/audit/auditd.conf -p wa
❷
-w /etc/audit/audit.rules -p wa
-w /etc/libaudit.conf -p wa
-w /etc/sysconfig/auditd -p wa
Introducing an Audit Rule Set
425
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......