public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Audit config for NISPOM req's
@ 2006-12-22 13:38 Curtas, Anthony R.
  2006-12-22 14:19 ` Steve Grubb
  0 siblings, 1 reply; 14+ messages in thread
From: Curtas, Anthony R. @ 2006-12-22 13:38 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1340 bytes --]

Hello all,

I've been a linux sysadmin for a while for a small network of systems
under the oversight of the Defense Security Service (DSS).  They have
always given us grief over Linux's inability to log certain events.  A
year ago, I implemented Snare with good results, but lack of a Kernel
panic on audit failure always had them second guessing our setup.  So
I'm encouraged to see the progress made here and am preparing to try
again.

 

Basically, the requirements are to log improper read access to certain
files (audit logs, shadow) and write access to many others (most of
/etc), and in some cases attempts to execute programs like stunnel and
su.

 

My main confusion on getting started is the difference between syscalls
and watches.  It seems watches can do almost all of what I need, but
they seem to be less "configurable" than the syscalls (like ignoring if
root changes anything).  Can someone explain the difference and where
one is more appropriate than the other.

 

I have the CAPP documents from HP and IBM, which seem to be a good
starting point (especially the conf files) - but I'm trying to
understand it all before implementation in case I need to tweak it.

 

Thanks in advance for any help,

Anthony

 

 

_____________

Anthony Curtas

SAIC, Division 35

 


[-- Attachment #1.2: Type: text/html, Size: 4293 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2007-01-16 16:15 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-12-22 13:38 Audit config for NISPOM req's Curtas, Anthony R.
2006-12-22 14:19 ` Steve Grubb
2006-12-22 15:08   ` Curtas, Anthony R.
2006-12-22 15:33     ` Steve Grubb
2006-12-22 16:22       ` Wieprecht, Karen M.
2006-12-22 16:25         ` Steve Grubb
2007-01-11 19:18       ` Wieprecht, Karen M.
2007-01-11 19:42         ` Steve Grubb
2007-01-12 16:09         ` Kirkwood, David A.
2007-01-12 16:38           ` Steve Grubb
2007-01-12 18:45             ` Kirkwood, David A.
2007-01-12 19:49               ` Steve Grubb
2007-01-16 15:51                 ` Kirkwood, David A.
2007-01-16 16:15                   ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox