From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eytan Naim Subject: Set audisp plugin filters Date: Wed, 12 Apr 2017 08:28:02 +0000 Message-ID: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============4017633432713888794==" Return-path: Received: from mx1.redhat.com (ext-mx08.extmail.prod.ext.phx2.redhat.com [10.5.110.32]) by smtp.corp.redhat.com (Postfix) with ESMTPS id AE3821716C for ; Wed, 12 Apr 2017 08:28:10 +0000 (UTC) Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0102.outbound.protection.outlook.com [104.47.42.102]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id AC7EEC05974B for ; Wed, 12 Apr 2017 08:28:05 +0000 (UTC) Content-Language: en-US List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: "linux-audit@redhat.com" List-Id: linux-audit@redhat.com --===============4017633432713888794== Content-Language: en-US Content-Type: multipart/related; boundary="_004_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_"; type="multipart/alternative" --_004_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_ Content-Type: multipart/alternative; boundary="_000_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_" --_000_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi, I am currently developing an audisp plugin that should be as effective as p= ossible. Therefore, I want to set my own set of filtering rules (2-3 syscalls) and I= don't want to get any other audit events from the audisp itself, - I assum= ed it is possible to set my own plugin rules but I couldn't find it in the = audit documentation (Linux Audit API) nor any other audisp plugins examples= . Is it even possible? If not, is it possible to run an auditd of my own in parallel with the orig= inal auditd? I assume each auditd can define its own set of audit rules. - = Am I right? Thanks in advance, [https://signature.imperva.com/assets/imperva-logo.png] Eytan Naim | SW Engineer eytan.naim@imperva.com | m: +972 50-225-8833 imperva.com | facebook | linkedin | twitter --_000_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

Hi,


I am currently developing an audisp plugin that should be as effective as p= ossible.

Therefore, I want to set my own set of filtering rules (2-3 syscalls= ) and I don't want to get any other audit events from the audisp itself, - = I assumed it is possible to set my own plugin rules but I couldn’t find it in the audit documentation (Linu= x Audit API) nor any other audisp plugins examples. Is it even possible?

If not, is it possible to run an auditd of my own in parallel with t= he original auditd? I assume each auditd can define its own set of audit ru= les. – Am I right?

 

Thanks in advance,

 

3D"https://signature.imp=
Eytan Naim | SW Engineer
eytan.naim@imperva.com | m: &#= 43;972 50-225-8833

imperva.com | facebook | <= span style=3D"color:#2E1A45">linkedin | twitter

 

--_000_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_-- --_004_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_ Content-Type: image/png; name="image001.png" Content-Description: image001.png Content-Disposition: inline; filename="image001.png"; size=1488; creation-date="Wed, 12 Apr 2017 08:28:02 GMT"; modification-date="Wed, 12 Apr 2017 08:28:02 GMT" Content-ID: Content-Transfer-Encoding: base64 iVBORw0KGgoAAAANSUhEUgAAAHsAAAAUCAMAAACau7LCAAAB/lBMVEUAAAAvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUv GkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkUvGkXX6PuGAAAAqXRSTlMAAQIDBAUG BwkLDA8QERITFBUWFxgaHB0eICIkJyssMDEyMzQ2ODo8PT5AQkRGR0hKTU5QVFZXWFlaW1xdXmBi Y2RnaWptbm9wc3V4eXp7fH1+f4CBgoOEhYeIiYqMjZCRkpOVlpiZmpydnqCio6WnqKqusLG0uLq8 vcDBxMXGx8jJysvMzdDR1NXX2Nzd3t/g4uPk5ufo6err7O3v8PHy8/T19vf4+vz+zrWi1gAAAthJ REFUSIntletbTFEUxt9SIyUil9JlMrooREaUFKEc5VrKrSSimHIbd7mFhFBUiEGiOv+l/e69z8xp jtHz9JX1Yda79l57/9ZZs84MfMLaADT4pDVBW6mKG4Rs81l2vq4wlpvNPrulAJXB4OLJskQgj7I9 1rosh2El4JEpHS4gv/nAUpjCAmK711SWrbLjPqqwV+iAabM3eWJlwL5iugGfPR6vxvzvFFss9i1G 4uANlSCqKKot3uhgd6nsXWYEtvl1+Uxs0yzDKboHGp3F4C6QqbdfRsO76XCGgz2RzOw5/eHsbr// +ju51KTZb3u1pWv2a7/f/1hdjpRJeo9iX6YuBLqs2opEHUvgYJt1zC62oiC7QIi5T2QVmu1FyCS7 heqgPJaIS3SdcnMF6+iBqueDvoLmYI+IScBTduBbOBs1VH1/ZafLS1LhCTXxrM5upd/Zzc9cB3vo PaNtwFr6jgEHu43qoWa3VmhbYGerjiUAd6wmJv1kwVFI+iH8oKuE69cc7AH5XD1qLifTprEr3e7s mgmqM5Fm7Z5hGC1jVP3i1AaKYdHERgox8kfoq+Bi16fSHewEttnMWcnPK5jGDlnWzHNeIk5F9VGV Iv4zi4lB/ChriQOOcr3dwUYzw91yLjMisA8h0pxb9qtcdnQ79SPsodsB5feu8XqrZE6yg81RDGRy Hv34I/vVZiDSrH0SdUxR5Ms11zB17qDJbxmx9KPuKeuiYw42X43jci6zw9hGgbDVKQoVec47KZ5F y8X91HJ8q4Fy+n2h/nyJd7CzzIkMzuVNhLELbCTFvmBoW2Rjp8pxrJBZiWOaMxKHqBfkrJoMddBw sHG7o9FCzcAOmtv+jsmXeGieTDutE2rF7zd9/UK3tHMMBmMc7HUezmU3ZsteLB+2QaalqscMiPbe F34sSR9Pk8tbHWwYXFk/a7Z6jceXSX1V7teL/1T6E8Hz8nfnOf7bP2W/AY8mEnxIatpfAAAAAElF TkSuQmCC --_004_BL2PR06MB212974A3256E375D116EC57383030BL2PR06MB2129namp_-- --===============4017633432713888794== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============4017633432713888794==-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Richard Guy Briggs Subject: Re: Set audisp plugin filters Date: Wed, 12 Apr 2017 11:54:31 -0400 Message-ID: <20170412155431.GN1572@madcap2.tricolour.ca> References: Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Content-Disposition: inline In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Eytan Naim Cc: "linux-audit@redhat.com" List-Id: linux-audit@redhat.com On 2017-04-12 08:28, Eytan Naim wrote: > Hi, Hi Eytan, > I am currently developing an audisp plugin that should be as effective as possible. > Therefore, I want to set my own set of filtering rules (2-3 syscalls) and I don't want to get any other audit events from the audisp itself, - I assumed it is possible to set my own plugin rules but I couldn't find it in the audit documentation (Linux Audit API) nor any other audisp plugins examples. Is it even possible? There is only one set of rules. You may need to add extra functionality to your plugin to do additional filtering, but I'll defer to Steve who would be better able to advise. > If not, is it possible to run an auditd of my own in parallel with the original auditd? I assume each auditd can define its own set of audit rules. - Am I right? At the moment there can only be one audit daemon registered with the kernel at a time. There are ideas floating around to have more than one audit daemon running in the future, but that is specifically to support containers and is most likely to be tied to a single instance per user namespace with its own ruleset. I suspect is isn't the answer you were seeking. > Eytan Naim | SW Engineer - RGB -- Richard Guy Briggs Sr. S/W Engineer, Kernel Security, Base Operating Systems Remote, Ottawa, Red Hat Canada IRC: rgb, SunRaycer Voice: +1.647.777.2635, Internal: (81) 32635 From mboxrd@z Thu Jan 1 00:00:00 1970 From: Paul Moore Subject: Re: Set audisp plugin filters Date: Wed, 12 Apr 2017 11:56:29 -0400 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: Received: from mx1.redhat.com (ext-mx08.extmail.prod.ext.phx2.redhat.com [10.5.110.32]) by smtp.corp.redhat.com (Postfix) with ESMTPS id AFC5378A30 for ; Wed, 12 Apr 2017 15:56:31 +0000 (UTC) Received: from mail-ua0-f170.google.com (mail-ua0-f170.google.com [209.85.217.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 763EBC059747 for ; Wed, 12 Apr 2017 15:56:30 +0000 (UTC) Received: by mail-ua0-f170.google.com with SMTP id u103so18821552uau.1 for ; Wed, 12 Apr 2017 08:56:30 -0700 (PDT) In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Eytan Naim Cc: "linux-audit@redhat.com" List-Id: linux-audit@redhat.com T24gV2VkLCBBcHIgMTIsIDIwMTcgYXQgNDoyOCBBTSwgRXl0YW4gTmFpbSA8ZXl0YW4ubmFpbUBp bXBlcnZhLmNvbT4gd3JvdGU6Cj4gSGksCj4KPiBJIGFtIGN1cnJlbnRseSBkZXZlbG9waW5nIGFu IGF1ZGlzcCBwbHVnaW4gdGhhdCBzaG91bGQgYmUgYXMgZWZmZWN0aXZlIGFzIHBvc3NpYmxlLgo+ Cj4gVGhlcmVmb3JlLCBJIHdhbnQgdG8gc2V0IG15IG93biBzZXQgb2YgZmlsdGVyaW5nIHJ1bGVz ICgyLTMgc3lzY2FsbHMpIGFuZCBJIGRvbid0IHdhbnQgdG8gZ2V0IGFueSBvdGhlciBhdWRpdCBl dmVudHMgZnJvbSB0aGUgYXVkaXNwIGl0c2VsZiwgLSBJIGFzc3VtZWQgaXQgaXMgcG9zc2libGUg dG8gc2V0IG15IG93biBwbHVnaW4gcnVsZXMgYnV0IEkgY291bGRu4oCZdCBmaW5kIGl0IGluIHRo ZSBhdWRpdCBkb2N1bWVudGF0aW9uIChMaW51eCBBdWRpdCBBUEkpIG5vciBhbnkgb3RoZXIgYXVk aXNwIHBsdWdpbnMgZXhhbXBsZXMuIElzIGl0IGV2ZW4gcG9zc2libGU/Cj4KPiBJZiBub3QsIGlz IGl0IHBvc3NpYmxlIHRvIHJ1biBhbiBhdWRpdGQgb2YgbXkgb3duIGluIHBhcmFsbGVsIHdpdGgg dGhlIG9yaWdpbmFsIGF1ZGl0ZD8gSSBhc3N1bWUgZWFjaCBhdWRpdGQgY2FuIGRlZmluZSBpdHMg b3duIHNldCBvZiBhdWRpdCBydWxlcy4g4oCTIEFtIEkgcmlnaHQ/CgpJJ2xsIGxldCBTdGV2ZSBH cnViYiByZXNwb25kIHdpdGggcmVzcGVjdCB0byB0aGUgYXVkaXQgZGlzcGF0Y2hlciwgYnV0CmFz IGZhciBhcyB0aGUgYXVkaXQgZGFlbW9uIGlzIGNvbmNlcm5lZCB5b3UgY2FuIGN1cnJlbnRseSBv bmx5IHJ1biBvbmUKaW5zdGFuY2UgYXQgYSB0aW1lIGFuZCBvbmx5IG9uZSBzZXQgb2YgYXVkaXQg ZmlsdGVyIHJ1bGVzIHRoYXQgYXBwbHkKdG8gdGhlIGVudGlyZSBzeXN0ZW0uCgotLSAKcGF1bCBt b29yZQp3d3cucGF1bC1tb29yZS5jb20KCi0tCkxpbnV4LWF1ZGl0IG1haWxpbmcgbGlzdApMaW51 eC1hdWRpdEByZWRoYXQuY29tCmh0dHBzOi8vd3d3LnJlZGhhdC5jb20vbWFpbG1hbi9saXN0aW5m by9saW51eC1hdWRpdA== From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: Set audisp plugin filters Date: Wed, 12 Apr 2017 12:45:47 -0400 Message-ID: <2095493.9BRLS0f1nT@x2> References: Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com Cc: Eytan Naim List-Id: linux-audit@redhat.com On Wednesday, April 12, 2017 4:28:02 AM EDT Eytan Naim wrote: > I am currently developing an audisp plugin that should be as effective as > possible. Therefore, I want to set my own set of filtering rules (2-3 > syscalls) and I don't want to get any other audit events from the audisp > itself This is not possible. There is one audit rule evaluator in the kernel. Any event generated by it will get written to disk and sent to all plugins. It is up to the plugins to filter events themselves. A long time ago, I was working on feeding an intrusion detection system. (I'm working my way back to intrusion detection and prevention but this time with better technology.) The way that I denoted events that were meant for the IDS system was to use keys with a special prefix of 'ids-'. Anything that did not have this prefix was discarded by the plugin. I have also considered asking if we could put a routing field in the event specifically for cases like this. There are times you want lots of information about something but its not actually meant to be logged. For example, you might want exit_group events which is not called out for in any security policy. So, you don't want to pollute the audit trail with those kind of events. I suppose this could be accomplished by using multiple keys with one having routing information. I don't exactly like that because it forces all keys associated with that event to get encoded and that takes up more disk space. Still mulling it over. Haven't solved it yet because I'm not quite ready to go back to IDS work just yet. > , - I assumed it is possible to set my own plugin rules but I couldn't find > it in the audit documentation (Linux Audit API) The preferred way is drop your rules into /etc/audit/rules.d/ This will get picked up and loaded. If however you wanted load them programmatically, I would suggest looking over the autrace source code. https://github.com/linux-audit/audit-userspace/blob/master/src/autrace.c#L50 There's no guarantee that the rule won't get flushed by someone updating the rules with augenrules unless you put the audit system into immutable mode. Some people may not like that. > nor any other audisp plugins examples. Is it even possible? If not, is it > possible to run an auditd of my own in parallel with the original auditd? Not exactly. There is a multicast socket with lower reliability guarantees but you get the same events that auditd sees. > I assume each auditd can define its own set of audit rules. - Am I right? Nope. -Steve