µ±Ç°Î»ÖÃ: > Linux°²È« >

Auditd - Linux ·þÎñÆ÷°²È«Éó¼Æ¹¤¾ß

ʱ¼ä:2015-02-18 19:56À´Ô´:linux.it.net.cn ×÷Õß:IT

Ê×ÏÈ£¬LinuxÖйú×£ºØ¶ÁÕß 2015ÑòÄê´º½Ú¿ìÀÖ£¬ÍòÊÂÈçÒ⣡ ¡£ÏÂÃ濪ʼÕâ¸öÐÂÄê°æÉó¼Æ¹¤¾ßµÄ½éÉÜ¡£

°²È«·À»¤ÊÇÊ×ÏÈÒª¿¼ÂǵÄÎÊÌ⡣ΪÁ˱ÜÃâ±ðÈ˵ÁÈ¡ÎÒÃǵÄÊý¾Ý£¬ÎÒÃÇÐèҪʱ¿Ì¹Ø×¢Ëü¡£°²È«·À»¤°üÀ¨ºÜ¶à¶«Î÷£¬Éó¼ÆÊÇÆäÖÐÖ®Ò»¡£

ÎÒÃÇÖªµÀLinuxϵͳÉÏÓÐÒ»¸ö½Ð auditd µÄÉó¼Æ¹¤¾ß¡£Õâ¸ö¹¤¾ßÔÚ´ó¶àÊýLinux²Ù×÷ϵͳÖÐÊÇĬÈÏ°²×°µÄ¡£ÄÇôauditd ÊÇʲô£¿¸ÃÈçºÎʹÓÃÄØ£¿ÏÂÃæÎÒÃÇ¿ªÊ¼½éÉÜ¡£

 

ʲôÊÇauditd£¿

auditd£¨»ò auditd ÊØ»¤½ø³Ì£©ÊÇLinuxÉó¼ÆϵͳÖÐÓû§¿Õ¼äµÄÒ»¸ö×é¼þ£¬Æ为Ôð½«Éó¼Æ¼Ç¼дÈë´ÅÅÌ¡£

°²×° auditd

UbuntuϵͳÖУ¬ÎÒÃÇ¿ÉÒÔʹÓàwajig ¹¤¾ß»òÕß apt-get ¹¤¾ß °²×°auditd¡£

°´ÕÕÏÂÃæµÄ˵Ã÷°²×°auditd£¬°²×°Íê±Ïºó½«×Ô¶¯°²×°ÒÔÏÂauditdºÍÏà¹ØµÄ¹¤¾ß£º

  • auditctl : ¼´Ê±¿ØÖÆÉó¼ÆÊØ»¤½ø³ÌµÄÐÐΪµÄ¹¤¾ß£¬±ÈÈçÈçÌí¼Ó¹æÔòµÈµÈ¡£
  • /etc/audit/audit.rules : ¼Ç¼Éó¼Æ¹æÔòµÄÎļþ¡£
  • aureport : ²é¿´ºÍÉú³ÉÉó¼Æ±¨¸æµÄ¹¤¾ß¡£
  • ausearch : ²éÕÒÉó¼ÆʼþµÄ¹¤¾ß
  • auditspd : ×ª·¢Ê¼þ֪ͨ¸øÆäËûÓ¦ÓóÌÐò£¬¶ø²»ÊÇдÈëµ½Éó¼ÆÈÕÖ¾ÎļþÖС£
  • autrace : Ò»¸öÓÃÓÚ¸ú×Ù½ø³ÌµÄÃüÁî¡£
  • /etc/audit/auditd.conf : auditd¹¤¾ßµÄÅäÖÃÎļþ¡£

Ê״ΰ²×° auditd ºó, Éó¼Æ¹æÔòÊǿյġ£

¿ÉÒÔʹÓÃÒÔÏÂÃüÁî²é¿´£º


  1. $ sudo auditctl -l

ÒÔÏÂÎÒÃǽéÉÜÈçºÎ¸øauditdÌí¼ÓÉó¼Æ¹æÔò¡£

ÈçºÎʹÓÃauditd

Audit ÎļþºÍĿ¼·ÃÎÊÉó¼Æ

ÎÒÃÇʹÓÃÉó¼Æ¹¤¾ßµÄÒ»¸ö»ù±¾µÄÐèÇóÊǼà¿ØÎļþºÍĿ¼µÄ¸ü¸Ä¡£Ê¹ÓÃauditd¹¤¾ß£¬ÎÒÃÇ¿Éͨ¹ýÈçÏÂÃüÁîÀ´ÅäÖÃ(×¢Ò⣬ÒÔÏÂÃüÁîÐèÒªrootȨÏÞ)¡£

ÎļþÉó¼Æ


  1. $ sudo auditctl -w /etc/passwd -p rwxa

Ñ¡Ïî :

  • -w path : Ö¸¶¨Òª¼à¿ØµÄ·¾¶£¬ÉÏÃæµÄÃüÁîÖ¸¶¨Á˼à¿ØµÄÎļþ·¾¶ /etc/passwd
  • -p : Ö¸¶¨´¥·¢Éó¼ÆµÄÎļþ/Ŀ¼µÄ·ÃÎÊȨÏÞ
  • rwxa £º Ö¸¶¨µÄ´¥·¢Ìõ¼þ£¬r ¶ÁȡȨÏÞ£¬w дÈëȨÏÞ£¬x Ö´ÐÐȨÏÞ£¬a ÊôÐÔ£¨attr£©

Ŀ¼Éó¼Æ

ʹÓÃÀàËƵÄÃüÁîÀ´¶ÔĿ¼½øÐÐÉó¼Æ£¬ÈçÏ£º


  1. $ sudo auditctl -w /production/

ÒÔÉÏÃüÁ¼à¿Ø¶Ô /production Ŀ¼ µÄËùÓзÃÎÊ¡£

ÏÖÔÚ£¬ÔËÐРauditctl -l ÃüÁî¼´¿É²é¿´ËùÓÐÒÑÅäÖõĹæÔò¡£

ÏÂÃ濪ʼ½éÉÜÉó¼ÆÈÕÖ¾¡£

²é¿´Éó¼ÆÈÕÖ¾

Ìí¼Ó¹æÔòºó£¬ÎÒÃÇ¿ÉÒԲ鿴 auditd µÄÈÕÖ¾¡£Ê¹Óàausearch ¹¤¾ß¿ÉÒԲ鿴auditdÈÕÖ¾¡£

ÎÒÃÇÒѾ­Ìí¼Ó¹æÔò¼à¿Ø /etc/passwd Îļþ¡£ÏÖÔÚ¿ÉÒÔʹÓàausearch ¹¤¾ßµÄÒÔÏÂÃüÁîÀ´²é¿´Éó¼ÆÈÕÖ¾ÁË¡£


  1. $ sudo ausearch -f /etc/passwd
  • -f É趨ausearch µ÷³ö /etc/passwdÎļþµÄÉó¼ÆÄÚÈÝ

ÏÂÃæÊÇÊä³ö £º

time->Mon Dec 22 09:39:16 2014

type=PATH msg=audit(1419215956.471:194): item=0 name="/etc/passwd" inode=142512 dev=08:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL

type=CWD msg=audit(1419215956.471:194): cwd="/home/pungki"

type=SYSCALL msg=audit(1419215956.471:194): arch=40000003 syscall=5 success=yes exit=3 a0=b779694b a1=80000 a2=1b6 a3=b8776aa8 items=1 ppid=2090 pid=2231 auid=4294967295 uid=1000 gid=1000 euid=0 suid=0 fsuid=0 egid=1000 sgid=1000 fsgid=1000 tty=pts0 ses=4294967295 comm="sudo" exe="/usr/bin/sudo" key=(null)

ÏÂÃ濪ʼ½â¶ÁÊä³ö½á¹û¡£

  • time : Éó¼Æʱ¼ä¡£
  • name : Éó¼Æ¶ÔÏó
  • cwd : µ±Ç°Â·¾¶
  • syscall : Ïà¹ØµÄϵͳµ÷ÓÃ
  • auid : Éó¼ÆÓû§ID
  • uid ºÍ gid : ·ÃÎÊÎļþµÄÓû§IDºÍÓû§×éID
  • comm : Óû§·ÃÎÊÎļþµÄÃüÁî
  • exe : ÉÏÃæÃüÁîµÄ¿ÉÖ´ÐÐÎļþ·¾¶

ÒÔÉÏÉó¼ÆÈÕÖ¾ÏÔʾÎļþδ±»¸Ä¶¯¡£

ÒÔÏÂÎÒÃǽ«ÒªÌí¼ÓÒ»¸öÓû§£¬¿´¿´auditdÈçºÎ¼Ç¼Îļþ /etc/passwdµÄ¸Ä¶¯µÄ¡£

time->Mon Dec 22 11:25:23 2014

type=PATH msg=audit(1419222323.628:510): item=1 name="/etc/passwd.lock" inode=143992 dev=08:01 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=DELETE

type=PATH msg=audit(1419222323.628:510): item=0 name="/etc/" inode=131073 dev=08:01 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT

type=CWD msg=audit(1419222323.628:510): cwd="/root"

type=SYSCALL msg=audit(1419222323.628:510): arch=40000003 syscall=10 success=yes exit=0 a0=bfc0ceec a1=0 a2=bfc0ceec a3=897764c items=2 ppid=2978 pid=2994 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="chfn" exe="/usr/bin/chfn" key=(null)

ÎÒÃÇ¿ÉÒÔ¿´µ½£¬ÔÚÖ¸¶¨µÄʱ¼ä£¬/etc/passwd ** ±»rootÓû§(uid =0, gid=0)ÔÚ/rootĿ¼ÏÂÐ޸ġ£/etc/passwd ÎļþÊÇʹÓÃ/usr/bin/chfn** ·ÃÎʵġ£

¼üÈë man chfn ¿ÉÒԲ鿴ÓйØchfn¸ü¶àµÄÐÅÏ¢¡£

ÏÂÃæÎÒÃÇ¿´ÁíÍâÒ»¸öÀý×Ó¡£

ÎÒÃÇÒѾ­ÅäÖÃauditdÈ¥¼à¿ØĿ¼ /production/ ÁË¡£ÕâÊǸöÐÂĿ¼¡£ËùÒÔÎÒÃÇÓÃausearchÈ¥²é¿´ÈÕÖ¾µÄʱºò»á·¢ÏÖʲô¶¼Ã»ÓС£

ÏÂÒ»²½£¬Ê¹ÓÃrootÕË»§µÄlsÃüÁîÁгö /production/ ϵÄÎļþÐÅÏ¢¡£ÔÙ´ÎʹÓÃausearchºó£¬½«»áÏÔʾһЩÐÅÏ¢¡£

time->Mon Dec 22 14:18:28 2014 type=PATH msg=audit(1419232708.344:527): item=0 name="/production/" inode=797104 dev=08:01 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL type=CWD msg=audit(1419232708.344:527): cwd="/root" type=SYSCALL msg=audit(1419232708.344:527): arch=40000003 syscall=295 success=yes exit=3 a0=ffffff9c a1=95761e8 a2=98800 a3=0 items=1 ppid=3033 pid=3444 auid=4294967295 uid=0 gid=0euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="ls" exe="/bin/ls"key=(null)

ºÍÉÏÒ»¸öÒ»Ñù£¬¿ÉÒԵóörootÕË»§Ê¹ÓÃlsÃüÁî·ÃÎÊÁË/production/Ŀ¼£¬lsÃüÁîµÄÎļþĿ¼ÊÇ /bin/ls

²é¿´Éó¼Æ±¨¸æ

Ò»µ©¶¨ÒåÉó¼Æ¹æÔòºó£¬Ëü»á×Ô¶¯ÔËÐС£¹ýÒ»¶Îʱ¼äºó£¬ÎÒÃÇ¿ÉÒÔ¿´¿´auditdÊÇÈçºÎ°ïÎÒÃǸú×ÙÉó¼ÆµÄ¡£

AuditdÌṩÁËÁíÒ»¸ö¹¤¾ß½Ð aureport ¡£´ÓÃû×ÖÉÏ¿ÉÒԲµ½£¬ aureport ÊÇʹÓÃϵͳÉó¼ÆÈÕÖ¾Éú³É¼òÒª±¨¸æµÄ¹¤¾ß¡£

ÎÒÃÇÒѾ­ÅäÖÃauditdÈ¥¸ú×Ù/etc/passwdÎļþ¡£auditd²ÎÊýÉèÖúóÒ»¶Îʱ¼äºó£¬audit.log Îļþ¾Í´´½¨³öÀ´ÁË¡£

Éú³ÉÉó¼Æ±¨¸æ£¬ÎÒÃÇ¿ÉÒÔʹÓÃaureport¹¤¾ß¡£²»´ø²ÎÊýÔËÐеĻ°£¬¿ÉÒÔÉú³ÉÉó¼Æ»î¶¯µÄ¸ÅÊö¡£


  1. $ sudo aureport

ÈçÉÏ£¬±¨¸æ°üº¬ÁË´ó¶àÊýÖØÒªÇøÓòµÄÐÅÏ¢¡£

ÉÏͼ¿ÉÒÔ¿´³öÓР3 ´ÎÊÚȨʧ°Ü¡£ ʹÓÃaureport£¬ÎÒÃÇ¿ÉÒÔÉîÈë²é¿´ÕâЩÐÅÏ¢¡£

ʹÓÃÒÔÏÂÃüÁî²é¿´ÊÚȨʧ°ÜµÄÏêϸÐÅÏ¢£º


  1. $ sudo aureport -au

´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬ÓÉÁ½¸öÓû§ÔÚÌض¨µÄʱ¼äÊÚȨʧ°Ü¡£

Èç¹ûÎÒÃÇÏë¿´ËùÓÐÕË»§ÐÞ¸ÄÏà¹ØµÄʼþ£¬¿ÉÒÔʹÓÃ-m²ÎÊý¡£


  1. $ sudo aureport -m

Auditd ÅäÖÃÎļþ

ÎÒÃÇÒѾ­Ìí¼ÓÈçϹæÔò£º

  • $ sudo auditctl -w /etc/passwd -p rwxa
  • $ sudo auditctl -w /production/

ÏÖÔÚ£¬Èç¹ûÈ·ÐÅÕâЩ¹æÔò¿ÉÒÔÕý³£¹¤×÷£¬ÎÒÃÇ¿ÉÒÔ½«ÆäÌí¼Óµ½/etc/audit/audit.rulesÖÐʹµÃ¹æÔòÓÀ¾ÃÓÐЧ¡£ÒÔϽéÉÜÈçºÎ½«ËûÃÇÌí¼Óµ½/etc/audit/audit.rulesÖÐÈ¥¡£

×îºó£¬±ðÍüÁËÖØÆôauditdÊØ»¤³ÌÐò


  1. # /etc/init.d/auditd restart

»ò


  1. # service auditd restart

×ܽá

AuditdÊÇLinuxÉϵÄÒ»¸öÉó¼Æ¹¤¾ß¡£Äã¿ÉÒÔÔĶÁauidtdÎĵµ»ñÈ¡¸ü¶àʹÓÃauditdºÍ¹¤¾ßµÄϸ½Ú¡£ÀýÈ磬ÊäÈë man auditd È¥¿´auditdµÄÏêϸ˵Ã÷£¬»òÕß¼üÈë man ausearch È¥¿´ÓÐ¹Ø ausearch ¹¤¾ßµÄÏêϸ˵Ã÷¡£

Çë½÷É÷´´½¨¹æÔò¡£Ì«¶à¹æÔò»áʹµÃÈÕÖ¾Îļþ¼±¾çÔö´ó£¡

via: http://linoxide.com/how-tos/auditd-tool-security-auditing/


 

(ÔðÈα༭£ºIT)
------·Ö¸ôÏß----------------------------
À¸Ä¿Áбí
ÍƼöÄÚÈÝ