Red Hatã®æ£®è¥ã§ãã
RHEL ã«ã¯ç£æ»ãã°ãåå¾ãã audit ã®ä»çµã¿ãããã¾ãã ç£æ»ãã°ã¨ã¯ã主ã«å種ã®ã»ãã¥ãªãã£è¦ä»¶ãæºãããããã·ã¹ãã ã§çºçããæ§ã ãªã¤ãã³ããæ¤åºãã¦è¨é²ããä»çµã¿ã§ãã
ãããããæå®ãããã¡ã¤ã«ã¸ã®ã¢ã¯ã»ã¹ãã·ã¹ãã ã³ã¼ã«ã®å¼åºããã³ãã³ãå®è¡ãèªè¨¼ãèªè¨¼ã®å¤±æããµã¼ãã¹ã®éå§ã»çµäºãªã©å¤æ°ã®ã¤ãã³ãããã°ã«ä¿åã§ãã¾ãã ãã¡ããç¡æå³ã«å¤§éã®ãã°ãåå¾ãã¦ãè² è·ããããã ãã§ãã®ã§ãå¿ è¦ãªãã®ã ããåå¾ãããã管çè ãã«ã¼ã«ãè¨å®ãã¾ãã
ç£æ»ã®ããã«ä½ãããä»çµã¿ã§ãããã·ã¹ãã ã®ãã©ãã«ã·ã¥ã¼ãã«ãæç¨ã§ãã ãã¨ãã°ãä½ããã®ããã»ã¹ xx ããã¡ã¤ã« /fuga/hoge ããã¾ã«æ´æ°ãã¦ãããxxãçºè¦ããããã®ãããªã±ã¼ã¹ã§å½¹ç«ã¡ã¾ãã
auditæ©è½æ¦è¦
linux kernelã«ã¯ç£æ»ãã°ãåå¾ããauditã®ä»çµã¿ãããã¾ãã
- ã·ã¹ãã ã³ã¼ã«å¼åºãããã®æåã»å¤±æã対象ã¨ãªããã¡ã¤ã«ãå©ç¨ããããã¡ã¤ã«åãSELinux ã³ã³ããã¹ããªã©ãæ¡ä»¶ã¨ãã¦ããããããã¤ãã³ããçºçãããæ¡ä»¶ã auditctl ã§æå®ãã¦ããã¾ãã
- å®éã«è©²å½ããã¤ãã³ããããã¨ãkauditdã«ã¤ãã³ããç»é²ããã¾ãã
linux kernelå ã ãã§ã¤ãã³ããåå¾ããããã§ã¯ãªããsystemdãPAMãshadow-utilsãªã©ãé£æºãã¦ãµã¼ãã¹ã®ã©ã¤ããµã¤ã¯ã«ãã¦ã¼ã¶èªè¨¼ã»ä½æã»åé¤ãªã©ã®ã¤ãã³ããåéãã¾ãã
auditç¨ã®netlinkã§auditdãsystemd-journaldãã¤ãã³ããåãã¨ã£ã¦ç£æ»ãã°ãä¿åãã¾ãã
- auditdã®ãã°ãããä»å±ãããã¼ã«ã使ã£ã¦å種ã®ã¬ãã¼ããçæã§ãã¾ãã
- audispdã¯ãauditãã°ã®å 容ã«ããé¢é£ããããã°ã©ã ãå®è¡ã§ãã¾ãã
- journalã§ã¯
journalctl _TRANSPORT=audit
ã¨ãããã¨ã§auditãã°ã ãã表示ãããã¨ãã§ãã¾ãã
auditæ©è½ã®é£ããã¨ãã
auditãä¸è¬ã®ã·ã¹ãã 管çè ãæ´»ç¨ããã«ã¯å°ããã¼ãã«ãããã¾ãã kernelã®ã·ã¹ãã ã³ã¼ã«ã¨ããæ¯è¼çä½ãã¬ãã«ã®ç¥èãå¿ è¦ã«ãªãç¹ã§ãã ãã®ããkernelãã·ã¹ãã ã³ã¼ã«ã«å ¨ã馴æã¿ããªãç¶æ ã§æ´»ç¨ãããã¨ã¯é£ããã§ãã
kernelãã·ã¹ãã ã³ã¼ã«ã«å¤å°é¦´æã¿ããã£ã¦ããããç®çã®ããã« ä½ãç£è¦ããã¨ããã®ãã¯ä¸è¬ã«èªæã§ã¯ããã¾ããã /usr/share/audit/sample-rules ãè¦ã㨠å種ã®ã»ãã¥ãªãã£è¦æ ¼ããã«ä½ãããã«ã¼ã«ãéç©ããã¦ãã¾ãã ãããèµ·ç¹ã«ãã¦èª¿ã¹ã¦ããã®ãããã§ãããã
ãã¨ãã° PCI DSS v3.1ããã®ã«ã¼ã«ã§ãã 30-pci-dss-v31.rules ã®ä¸ã«ã¯ ãã¦ã¼ã¶ãç£æ»ãã°ã¸ã¢ã¯ã»ã¹ãããã¨ããããã¨ãè¨é²ããããã«ä»¥ä¸ã®ãããªè¨å®ãããã¾ãã
## 10.2.3 Access to all audit trails. -a always,exit -F dir=/var/log/audit/ -F perm=r -F auid>=1000 -F auid!=unset -F key=10.2.3-access-audit-trail -a always,exit -F path=/usr/sbin/ausearch -F perm=x -F key=10.2.3-access-audit-trail -a always,exit -F path=/usr/sbin/aureport -F perm=x -F key=10.2.3-access-audit-trail -a always,exit -F path=/usr/sbin/aulast -F perm=x -F key=10.2.3-access-audit-trail -a always,exit -F path=/usr/sbin/aulastlogin -F perm=x -F key=10.2.3-access-audit-trail -a always,exit -F path=/usr/sbin/auvirt -F perm=x -F key=10.2.3-access-audit-trail
ããããã¼ã¯ã¼ããç´¹ä»ãã¾ãããªãã¨ãªãä¸ã®ã«ã¼ã«ãèªã¿ã¨ãããã¨æãã¾ãã 詳ãã㯠auditctl ã® man page ãåç §ãã¦ãã ããã
ãã¼ã¯ã¼ã | æå³ |
---|---|
always | ã·ã¹ãã ã³ã¼ã«éå§æã«audit contextãä¿åãã |
exit | ã·ã¹ãã ã³ã¼ã«ãçµäºããæã«ã¤ãã³ããè¨é²ãããã®å¤å®ãè¡ã |
dir, path | ã·ã¹ãã ã³ã¼ã«å¼æ°ã®ãã£ã¬ã¯ããªããã¹ |
perm | ã·ã¹ãã ã³ã¼ã«ãå¿ è¦ã¨ãã権é |
auid | æåã«ãã°ã¤ã³ããæã®UIDã(suãªã©ããã¦ãå¤æ´ãããªã) |
key | ãã°ã®ãã£ã«ã¿ç¨ã«è¨é²ãã key |
/var/log/audit/ãã£ã¬ã¯ããªã¸ã®èªã¿è¾¼ã¿ã¢ã¯ã»ã¹ããaudité¢é£ã®ã¬ãã¼ããåºåããã³ãã³ãå®è¡ã®ã¿ã¤ãã³ã°ã§ "10.2.3-access-audit-trail" ã¨ãã ãã¼ã¯ã¼ãã¤ãã§ç£æ»ãã°ã«è¨é²ããã¨ããã«ã¼ã«ã§ãã
auditæ©è½ãå©ç¨ããã¨ãã®æ å ±æº
RHEL㧠auditæ©è½ãå©ç¨ããæã«ã¯ã以ä¸ããã¥ã¡ã³ããåç §ãã¾ãã ãã®è¨äºã§ã¨ããããªãã£ã auditctl ã®å©ç¨æ¹æ³ããã«ã¼ã«ãã·ã¹ãã ã§æ°¸ç¶çã«å©ç¨ããããã® augenrules ã«ã¤ãã¦ã®èª¬æãããã¾ãã é¢é£ãã man pageããã²èªã¿ã¾ãããã
RHEL ããã¥ã¡ã³ã ãã»ãã¥ãªãã£ã¼ã®å¼·åãå ãã·ã¹ãã ã®ç£æ»ã access.redhat.com