Ê×ÏÈ£¬LinuxÖйú×£ºØ¶ÁÕß 2015ÑòÄê´º½Ú¿ìÀÖ£¬ÍòÊÂÈçÒ⣡ ¡£ÏÂÃæ¿ªÊ¼Õâ¸öÐÂÄê°æÉ󼯹¤¾ßµÄ½éÉÜ¡£ °²È«·À»¤ÊÇÊ×ÏÈÒª¿¼ÂǵÄÎÊÌ⡣ΪÁ˱ÜÃâ±ðÈ˵ÁÈ¡ÎÒÃǵÄÊý¾Ý£¬ÎÒÃÇÐèҪʱ¿Ì¹Ø×¢Ëü¡£°²È«·À»¤°üÀ¨ºÜ¶à¶«Î÷£¬Éó¼ÆÊÇÆäÖÐÖ®Ò»¡£ ÎÒÃÇÖªµÀLinuxϵͳÉÏÓÐÒ»¸ö½Ð auditd µÄÉ󼯹¤¾ß¡£Õâ¸ö¹¤¾ßÔÚ´ó¶àÊýLinux²Ù×÷ϵͳÖÐÊÇĬÈϰ²×°µÄ¡£ÄÇôauditd ÊÇʲô£¿¸ÃÈçºÎʹÓÃÄØ£¿ÏÂÃæÎÒÃÇ¿ªÊ¼½éÉÜ¡£
ʲôÊÇauditd£¿auditd£¨»ò auditd ÊØ»¤½ø³Ì£©ÊÇLinuxÉó¼ÆÏµÍ³ÖÐÓû§¿Õ¼äµÄÒ»¸ö×é¼þ£¬Æä¸ºÔð½«É󼯼ǼдÈë´ÅÅÌ¡£
°²×° auditdUbuntuϵͳÖУ¬ÎÒÃÇ¿ÉÒÔʹÓà wajig ¹¤¾ß»òÕß apt-get ¹¤¾ß °²×°auditd¡£
°´ÕÕÏÂÃæµÄ˵Ã÷°²×°auditd£¬°²×°Íê±Ïºó½«×Ô¶¯°²×°ÒÔÏÂauditdºÍÏà¹ØµÄ¹¤¾ß£º
Ê״ΰ²×° auditd ºó, É󼯹æÔòÊǿյġ£ ¿ÉÒÔʹÓÃÒÔÏÂÃüÁî²é¿´£º
ÒÔÏÂÎÒÃǽéÉÜÈçºÎ¸øauditdÌí¼ÓÉ󼯹æÔò¡£ ÈçºÎʹÓÃauditdAudit ÎļþºÍĿ¼·ÃÎÊÉó¼ÆÎÒÃÇʹÓÃÉ󼯹¤¾ßµÄÒ»¸ö»ù±¾µÄÐèÇóÊÇ¼à¿ØÎļþºÍĿ¼µÄ¸ü¸Ä¡£Ê¹ÓÃauditd¹¤¾ß£¬ÎÒÃÇ¿Éͨ¹ýÈçÏÂÃüÁîÀ´ÅäÖÃ(×¢Ò⣬ÒÔÏÂÃüÁîÐèÒªrootȨÏÞ)¡£ ÎļþÉó¼Æ
Ñ¡Ïî :
Ŀ¼Éó¼ÆÊ¹ÓÃÀàËÆµÄÃüÁîÀ´¶ÔĿ¼½øÐÐÉ󼯣¬ÈçÏ£º
ÒÔÉÏÃüÁ¼à¿Ø¶Ô /production Ŀ¼ µÄËùÓзÃÎÊ¡£ ÏÖÔÚ£¬ÔËÐÐ auditctl -l ÃüÁî¼´¿É²é¿´ËùÓÐÒÑÅäÖõĹæÔò¡£
ÏÂÃæ¿ªÊ¼½éÉÜÉó¼ÆÈÕÖ¾¡£ ²é¿´Éó¼ÆÈÕÖ¾Ìí¼Ó¹æÔòºó£¬ÎÒÃÇ¿ÉÒԲ鿴 auditd µÄÈÕÖ¾¡£Ê¹Óà ausearch ¹¤¾ß¿ÉÒԲ鿴auditdÈÕÖ¾¡£ ÎÒÃÇÒѾÌí¼Ó¹æÔò¼à¿Ø /etc/passwd Îļþ¡£ÏÖÔÚ¿ÉÒÔʹÓà ausearch ¹¤¾ßµÄÒÔÏÂÃüÁîÀ´²é¿´Éó¼ÆÈÕÖ¾ÁË¡£
ÏÂÃæÊÇÊä³ö £º
ÏÂÃæ¿ªÊ¼½â¶ÁÊä³ö½á¹û¡£
ÒÔÉÏÉó¼ÆÈÕÖ¾ÏÔʾÎļþδ±»¸Ä¶¯¡£ ÒÔÏÂÎÒÃǽ«ÒªÌí¼ÓÒ»¸öÓû§£¬¿´¿´auditdÈçºÎ¼Ç¼Îļþ /etc/passwdµÄ¸Ä¶¯µÄ¡£
ÎÒÃÇ¿ÉÒÔ¿´µ½£¬ÔÚÖ¸¶¨µÄʱ¼ä£¬/etc/passwd ** ±»rootÓû§(uid =0, gid=0)ÔÚ/rootĿ¼ÏÂÐ޸ġ£/etc/passwd ÎļþÊÇʹÓÃ/usr/bin/chfn** ·ÃÎʵġ£ ¼üÈë man chfn ¿ÉÒԲ鿴ÓйØchfn¸ü¶àµÄÐÅÏ¢¡£
ÏÂÃæÎÒÃÇ¿´ÁíÍâÒ»¸öÀý×Ó¡£ ÎÒÃÇÒѾÅäÖÃauditdÈ¥¼à¿ØÄ¿Â¼ /production/ ÁË¡£ÕâÊǸöÐÂĿ¼¡£ËùÒÔÎÒÃÇÓÃausearchÈ¥²é¿´ÈÕÖ¾µÄʱºò»á·¢ÏÖʲô¶¼Ã»ÓС£
ÏÂÒ»²½£¬Ê¹ÓÃrootÕË»§µÄlsÃüÁîÁгö /production/ ϵÄÎļþÐÅÏ¢¡£ÔÙ´ÎʹÓÃausearchºó£¬½«»áÏÔʾһЩÐÅÏ¢¡£
ºÍÉÏÒ»¸öÒ»Ñù£¬¿ÉÒԵóörootÕË»§Ê¹ÓÃlsÃüÁî·ÃÎÊÁË/production/Ŀ¼£¬lsÃüÁîµÄÎļþĿ¼ÊÇ /bin/ls ²é¿´É󼯱¨¸æÒ»µ©¶¨ÒåÉ󼯹æÔòºó£¬Ëü»á×Ô¶¯ÔËÐС£¹ýÒ»¶Îʱ¼äºó£¬ÎÒÃÇ¿ÉÒÔ¿´¿´auditdÊÇÈçºÎ°ïÎÒÃǸú×ÙÉ󼯵ġ£ AuditdÌṩÁËÁíÒ»¸ö¹¤¾ß½Ð aureport ¡£´ÓÃû×ÖÉÏ¿ÉÒԲµ½£¬ aureport ÊÇʹÓÃϵͳÉó¼ÆÈÕÖ¾Éú³É¼òÒª±¨¸æµÄ¹¤¾ß¡£ ÎÒÃÇÒѾÅäÖÃauditdÈ¥¸ú×Ù/etc/passwdÎļþ¡£auditd²ÎÊýÉèÖúóÒ»¶Îʱ¼äºó£¬audit.log Îļþ¾Í´´½¨³öÀ´ÁË¡£ Éú³ÉÉ󼯱¨¸æ£¬ÎÒÃÇ¿ÉÒÔʹÓÃaureport¹¤¾ß¡£²»´ø²ÎÊýÔËÐеϰ£¬¿ÉÒÔÉú³ÉÉó¼Æ»î¶¯µÄ¸ÅÊö¡£
ÈçÉÏ£¬±¨¸æ°üº¬ÁË´ó¶àÊýÖØÒªÇøÓòµÄÐÅÏ¢¡£ ÉÏͼ¿ÉÒÔ¿´³öÓÐ 3 ´ÎÊÚȨʧ°Ü¡£ ʹÓÃaureport£¬ÎÒÃÇ¿ÉÒÔÉîÈë²é¿´ÕâЩÐÅÏ¢¡£ ʹÓÃÒÔÏÂÃüÁî²é¿´ÊÚȨʧ°ÜµÄÏêϸÐÅÏ¢£º
´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬ÓÉÁ½¸öÓû§ÔÚÌØ¶¨µÄʱ¼äÊÚȨʧ°Ü¡£ Èç¹ûÎÒÃÇÏë¿´ËùÓÐÕË»§ÐÞ¸ÄÏà¹ØµÄʼþ£¬¿ÉÒÔʹÓÃ-m²ÎÊý¡£
Auditd ÅäÖÃÎļþÎÒÃÇÒѾÌí¼ÓÈçϹæÔò£º
ÏÖÔÚ£¬Èç¹ûÈ·ÐÅÕâЩ¹æÔò¿ÉÒÔÕý³£¹¤×÷£¬ÎÒÃÇ¿ÉÒÔ½«ÆäÌí¼Óµ½/etc/audit/audit.rulesÖÐʹµÃ¹æÔòÓÀ¾ÃÓÐЧ¡£ÒÔϽéÉÜÈçºÎ½«ËûÃÇÌí¼Óµ½/etc/audit/audit.rulesÖÐÈ¥¡£
×îºó£¬±ðÍüÁËÖØÆôauditdÊØ»¤³ÌÐò
»ò
×ܽáAuditdÊÇLinuxÉϵÄÒ»¸öÉ󼯹¤¾ß¡£Äã¿ÉÒÔÔĶÁauidtdÎĵµ»ñÈ¡¸ü¶àʹÓÃauditdºÍ¹¤¾ßµÄϸ½Ú¡£ÀýÈ磬ÊäÈë man auditd È¥¿´auditdµÄÏêϸ˵Ã÷£¬»òÕß¼üÈë man ausearch È¥¿´ÓÐ¹Ø ausearch ¹¤¾ßµÄÏêϸ˵Ã÷¡£ Çë½÷É÷´´½¨¹æÔò¡£Ì«¶à¹æÔò»áʹµÃÈÕÖ¾Îļþ¼±¾çÔö´ó£¡
via: http://linoxide.com/how-tos/auditd-tool-security-auditing/ |