Ê×ÏÈ£¬LinuxÖйú×£ºØ¶ÁÕß 2015ÑòÄê´º½Ú¿ìÀÖ£¬ÍòÊÂÈçÒ⣡ ¡£ÏÂÃ濪ʼÕâ¸öÐÂÄê°æÉó¼Æ¹¤¾ßµÄ½éÉÜ¡£ °²È«·À»¤ÊÇÊ×ÏÈÒª¿¼ÂǵÄÎÊÌ⡣ΪÁ˱ÜÃâ±ðÈ˵ÁÈ¡ÎÒÃǵÄÊý¾Ý£¬ÎÒÃÇÐèҪʱ¿Ì¹Ø×¢Ëü¡£°²È«·À»¤°üÀ¨ºÜ¶à¶«Î÷£¬Éó¼ÆÊÇÆäÖÐÖ®Ò»¡£ ÎÒÃÇÖªµÀLinuxϵͳÉÏÓÐÒ»¸ö½Ð auditd µÄÉó¼Æ¹¤¾ß¡£Õâ¸ö¹¤¾ßÔÚ´ó¶àÊýLinux²Ù×÷ϵͳÖÐÊÇĬÈÏ°²×°µÄ¡£ÄÇôauditd ÊÇʲô£¿¸ÃÈçºÎʹÓÃÄØ£¿ÏÂÃæÎÒÃÇ¿ªÊ¼½éÉÜ¡£
ʲôÊÇauditd£¿auditd£¨»ò auditd ÊØ»¤½ø³Ì£©ÊÇLinuxÉó¼ÆϵͳÖÐÓû§¿Õ¼äµÄÒ»¸ö×é¼þ£¬Æ为Ôð½«Éó¼Æ¼Ç¼дÈë´ÅÅÌ¡£
°²×° auditdUbuntuϵͳÖУ¬ÎÒÃÇ¿ÉÒÔʹÓà wajig ¹¤¾ß»òÕß apt-get ¹¤¾ß °²×°auditd¡£
°´ÕÕÏÂÃæµÄ˵Ã÷°²×°auditd£¬°²×°Íê±Ïºó½«×Ô¶¯°²×°ÒÔÏÂauditdºÍÏà¹ØµÄ¹¤¾ß£º
Ê״ΰ²×° auditd ºó, Éó¼Æ¹æÔòÊǿյġ£ ¿ÉÒÔʹÓÃÒÔÏÂÃüÁî²é¿´£º
ÒÔÏÂÎÒÃǽéÉÜÈçºÎ¸øauditdÌí¼ÓÉó¼Æ¹æÔò¡£ ÈçºÎʹÓÃauditdAudit ÎļþºÍĿ¼·ÃÎÊÉó¼ÆÎÒÃÇʹÓÃÉó¼Æ¹¤¾ßµÄÒ»¸ö»ù±¾µÄÐèÇóÊǼà¿ØÎļþºÍĿ¼µÄ¸ü¸Ä¡£Ê¹ÓÃauditd¹¤¾ß£¬ÎÒÃÇ¿Éͨ¹ýÈçÏÂÃüÁîÀ´ÅäÖÃ(×¢Ò⣬ÒÔÏÂÃüÁîÐèÒªrootȨÏÞ)¡£ ÎļþÉó¼Æ
Ñ¡Ïî :
Ŀ¼Éó¼ÆʹÓÃÀàËƵÄÃüÁîÀ´¶ÔĿ¼½øÐÐÉó¼Æ£¬ÈçÏ£º
ÒÔÉÏÃüÁ¼à¿Ø¶Ô /production Ŀ¼ µÄËùÓзÃÎÊ¡£ ÏÖÔÚ£¬ÔËÐÐ auditctl -l ÃüÁî¼´¿É²é¿´ËùÓÐÒÑÅäÖõĹæÔò¡£
ÏÂÃ濪ʼ½éÉÜÉó¼ÆÈÕÖ¾¡£ ²é¿´Éó¼ÆÈÕÖ¾Ìí¼Ó¹æÔòºó£¬ÎÒÃÇ¿ÉÒԲ鿴 auditd µÄÈÕÖ¾¡£Ê¹Óà ausearch ¹¤¾ß¿ÉÒԲ鿴auditdÈÕÖ¾¡£ ÎÒÃÇÒѾÌí¼Ó¹æÔò¼à¿Ø /etc/passwd Îļþ¡£ÏÖÔÚ¿ÉÒÔʹÓà ausearch ¹¤¾ßµÄÒÔÏÂÃüÁîÀ´²é¿´Éó¼ÆÈÕÖ¾ÁË¡£
ÏÂÃæÊÇÊä³ö £º
ÏÂÃ濪ʼ½â¶ÁÊä³ö½á¹û¡£
ÒÔÉÏÉó¼ÆÈÕÖ¾ÏÔʾÎļþδ±»¸Ä¶¯¡£ ÒÔÏÂÎÒÃǽ«ÒªÌí¼ÓÒ»¸öÓû§£¬¿´¿´auditdÈçºÎ¼Ç¼Îļþ /etc/passwdµÄ¸Ä¶¯µÄ¡£
ÎÒÃÇ¿ÉÒÔ¿´µ½£¬ÔÚÖ¸¶¨µÄʱ¼ä£¬/etc/passwd ** ±»rootÓû§(uid =0, gid=0)ÔÚ/rootĿ¼ÏÂÐ޸ġ£/etc/passwd ÎļþÊÇʹÓÃ/usr/bin/chfn** ·ÃÎʵġ£ ¼üÈë man chfn ¿ÉÒԲ鿴ÓйØchfn¸ü¶àµÄÐÅÏ¢¡£
ÏÂÃæÎÒÃÇ¿´ÁíÍâÒ»¸öÀý×Ó¡£ ÎÒÃÇÒѾÅäÖÃauditdÈ¥¼à¿ØĿ¼ /production/ ÁË¡£ÕâÊǸöÐÂĿ¼¡£ËùÒÔÎÒÃÇÓÃausearchÈ¥²é¿´ÈÕÖ¾µÄʱºò»á·¢ÏÖʲô¶¼Ã»ÓС£
ÏÂÒ»²½£¬Ê¹ÓÃrootÕË»§µÄlsÃüÁîÁгö /production/ ϵÄÎļþÐÅÏ¢¡£ÔÙ´ÎʹÓÃausearchºó£¬½«»áÏÔʾһЩÐÅÏ¢¡£
ºÍÉÏÒ»¸öÒ»Ñù£¬¿ÉÒԵóörootÕË»§Ê¹ÓÃlsÃüÁî·ÃÎÊÁË/production/Ŀ¼£¬lsÃüÁîµÄÎļþĿ¼ÊÇ /bin/ls ²é¿´Éó¼Æ±¨¸æÒ»µ©¶¨ÒåÉó¼Æ¹æÔòºó£¬Ëü»á×Ô¶¯ÔËÐС£¹ýÒ»¶Îʱ¼äºó£¬ÎÒÃÇ¿ÉÒÔ¿´¿´auditdÊÇÈçºÎ°ïÎÒÃǸú×ÙÉó¼ÆµÄ¡£ AuditdÌṩÁËÁíÒ»¸ö¹¤¾ß½Ð aureport ¡£´ÓÃû×ÖÉÏ¿ÉÒԲµ½£¬ aureport ÊÇʹÓÃϵͳÉó¼ÆÈÕÖ¾Éú³É¼òÒª±¨¸æµÄ¹¤¾ß¡£ ÎÒÃÇÒѾÅäÖÃauditdÈ¥¸ú×Ù/etc/passwdÎļþ¡£auditd²ÎÊýÉèÖúóÒ»¶Îʱ¼äºó£¬audit.log Îļþ¾Í´´½¨³öÀ´ÁË¡£ Éú³ÉÉó¼Æ±¨¸æ£¬ÎÒÃÇ¿ÉÒÔʹÓÃaureport¹¤¾ß¡£²»´ø²ÎÊýÔËÐеĻ°£¬¿ÉÒÔÉú³ÉÉó¼Æ»î¶¯µÄ¸ÅÊö¡£
ÈçÉÏ£¬±¨¸æ°üº¬ÁË´ó¶àÊýÖØÒªÇøÓòµÄÐÅÏ¢¡£ ÉÏͼ¿ÉÒÔ¿´³öÓÐ 3 ´ÎÊÚȨʧ°Ü¡£ ʹÓÃaureport£¬ÎÒÃÇ¿ÉÒÔÉîÈë²é¿´ÕâЩÐÅÏ¢¡£ ʹÓÃÒÔÏÂÃüÁî²é¿´ÊÚȨʧ°ÜµÄÏêϸÐÅÏ¢£º
´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬ÓÉÁ½¸öÓû§ÔÚÌض¨µÄʱ¼äÊÚȨʧ°Ü¡£ Èç¹ûÎÒÃÇÏë¿´ËùÓÐÕË»§ÐÞ¸ÄÏà¹ØµÄʼþ£¬¿ÉÒÔʹÓÃ-m²ÎÊý¡£
Auditd ÅäÖÃÎļþÎÒÃÇÒѾÌí¼ÓÈçϹæÔò£º
ÏÖÔÚ£¬Èç¹ûÈ·ÐÅÕâЩ¹æÔò¿ÉÒÔÕý³£¹¤×÷£¬ÎÒÃÇ¿ÉÒÔ½«ÆäÌí¼Óµ½/etc/audit/audit.rulesÖÐʹµÃ¹æÔòÓÀ¾ÃÓÐЧ¡£ÒÔϽéÉÜÈçºÎ½«ËûÃÇÌí¼Óµ½/etc/audit/audit.rulesÖÐÈ¥¡£
×îºó£¬±ðÍüÁËÖØÆôauditdÊØ»¤³ÌÐò
»ò
×ܽáAuditdÊÇLinuxÉϵÄÒ»¸öÉó¼Æ¹¤¾ß¡£Äã¿ÉÒÔÔĶÁauidtdÎĵµ»ñÈ¡¸ü¶àʹÓÃauditdºÍ¹¤¾ßµÄϸ½Ú¡£ÀýÈ磬ÊäÈë man auditd È¥¿´auditdµÄÏêϸ˵Ã÷£¬»òÕß¼üÈë man ausearch È¥¿´ÓÐ¹Ø ausearch ¹¤¾ßµÄÏêϸ˵Ã÷¡£ Çë½÷É÷´´½¨¹æÔò¡£Ì«¶à¹æÔò»áʹµÃÈÕÖ¾Îļþ¼±¾çÔö´ó£¡
via: http://linoxide.com/how-tos/auditd-tool-security-auditing/ |