From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: anom messages Date: Thu, 24 May 2018 12:35:18 -0400 Message-ID: <10392411.QvQxEpX8uf@x2> References: <3D2AB1326AB2974190FCE3F69401F790010BADD2C461@FRVDX103.fr01.awl.atosorigin.net> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <3D2AB1326AB2974190FCE3F69401F790010BADD2C461@FRVDX103.fr01.awl.atosorigin.net> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com Cc: Maupertuis Philippe List-Id: linux-audit@redhat.com Hello, On Thursday, May 24, 2018 11:06:11 AM EDT Maupertuis Philippe wrote: > The redhat security guide in annex B2 reads : > All Audit event types prepended with ANOM are intended to be processed by > an intrusion detection program. All Audit event types prepended with RESP > are intended responses of an intrusion detection system in case it detects > malicious activity on the system. > > Can you point me towards an intrusion detection program able to manage > these audit records. It is in development but not ready to merge into the audit-userspace repo. This is why I added some more event types in this area a couple months ago. It is targeted for the audit-3.1 release along with a bunch of new audit rules to assist in its job. Audit 3.1 should be late summer or fall of this year. -Steve