bk99.de entertain the web since 1997

Linux security monitoring with audit events

Summary

Hilko Bengen shows how Linux auditd delivers fine-grained host events and how the unwieldy format can be made usable for attack detection with reasonable effort. Network monitoring only detects many attacks together with context from the affected host. More telemetry only helps if events are reliably correlated and prioritised.

Ideas

  • Audit rules capture security-relevant system calls and object accesses.
  • Several raw events often belong to a single understandable action.
  • Normalisation translates kernel information into security events that can be evaluated.
  • Targeted rules avoid unnecessary data volumes and CPU load.

Recommendations

  • Start with a few events that answer concrete detection questions.
  • Measure data rate and processing effort before a broad rollout.

References

Watch the talk

Search the Web Archive