Linux security monitoring with audit events
Summary
Hilko Bengen shows how Linux auditd delivers fine-grained host events and how the unwieldy format can be made usable for attack detection with reasonable effort. Network monitoring only detects many attacks together with context from the affected host. More telemetry only helps if events are reliably correlated and prioritised.
Ideas
- Audit rules capture security-relevant system calls and object accesses.
- Several raw events often belong to a single understandable action.
- Normalisation translates kernel information into security events that can be evaluated.
- Targeted rules avoid unnecessary data volumes and CPU load.
Recommendations
- Start with a few events that answer concrete detection questions.
- Measure data rate and processing effort before a broad rollout.
References
Links to the original source and the Web Archive open in a new tab.