|
|
7629ac |
diff --git a/shared/checks/oval/directory_access_var_log_audit.xml b/shared/checks/oval/directory_access_var_log_audit.xml
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..8edc5970d3
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/shared/checks/oval/directory_access_var_log_audit.xml
|
|
|
7629ac |
@@ -0,0 +1,57 @@
|
|
|
7629ac |
+<def-group>
|
|
|
7629ac |
+ <definition class="compliance" id="directory_access_var_log_audit" version="1">
|
|
|
7629ac |
+ <metadata>
|
|
|
7629ac |
+ <title>Ensure auditd Collects Information Read Access to /var/log/audit</title>
|
|
|
7629ac |
+ <affected family="unix">
|
|
|
7629ac |
+ <platform>Red Hat Enterprise Linux 7</platform>
|
|
|
7629ac |
+ <platform>multi_platform_fedora</platform>
|
|
|
7629ac |
+ </affected>
|
|
|
7629ac |
+ <description>Audit rules about the read events to /var/log/audit</description>
|
|
|
7629ac |
+ </metadata>
|
|
|
7629ac |
+
|
|
|
7629ac |
+ <criteria operator="OR">
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+ <criteria operator="AND">
|
|
|
7629ac |
+ <extend_definition comment="audit augenrules" definition_ref="audit_rules_augenrules" />
|
|
|
7629ac |
+ <criterion comment="audit rule to record read access events to /var/log/audit" test_ref="test_directory_acccess_var_log_audit_augenrules" />
|
|
|
7629ac |
+ </criteria>
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+ <criteria operator="AND">
|
|
|
7629ac |
+ <extend_definition comment="audit auditctl" definition_ref="audit_rules_auditctl" />
|
|
|
7629ac |
+ <criterion comment="audit rule to record read access events to /var/log/audit" test_ref="test_directory_acccess_var_log_audit_auditctl" />
|
|
|
7629ac |
+ </criteria>
|
|
|
7629ac |
+
|
|
|
7629ac |
+ </criteria>
|
|
|
7629ac |
+ </definition>
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+ <constant_variable id="var_audit_rule_access_var_log_audit_regex" version="1" datatype="string" comment="audit rule arch and syscal">
|
|
|
7629ac |
+ <value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+dir=/var/log/audit/)[\s]+(?:-F[\s]+perm=r)[\s]+(?:-F\s+auid>={{{ auid }}}[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</value>
|
|
|
7629ac |
+ </constant_variable>
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+ comment="defined audit rule must exist" id="test_directory_acccess_var_log_audit_augenrules" version="1">
|
|
|
7629ac |
+ <ind:object object_ref="object_directory_acccess_var_log_audit_augenrules" />
|
|
|
7629ac |
+ </ind:textfilecontent54_test>
|
|
|
7629ac |
+ <ind:textfilecontent54_object id="object_directory_acccess_var_log_audit_augenrules" version="1">
|
|
|
7629ac |
+ <ind:filepath operation="pattern match">/etc/audit/rules\.d/.*\.rules</ind:filepath>
|
|
|
7629ac |
+ <ind:pattern operation="pattern match" var_ref="var_audit_rule_access_var_log_audit_regex" />
|
|
|
7629ac |
+ <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
|
|
|
7629ac |
+ </ind:textfilecontent54_object>
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+ comment="defined audit rule must exist" id="test_directory_acccess_var_log_audit_auditctl" version="1">
|
|
|
7629ac |
+ <ind:object object_ref="object_directory_acccess_var_log_audit_auditctl" />
|
|
|
7629ac |
+ </ind:textfilecontent54_test>
|
|
|
7629ac |
+ <ind:textfilecontent54_object id="object_directory_acccess_var_log_audit_auditctl" version="1">
|
|
|
7629ac |
+ <ind:filepath>/etc/audit/audit.rules</ind:filepath>
|
|
|
7629ac |
+ <ind:pattern operation="pattern match" var_ref="var_audit_rule_access_var_log_audit_regex" />
|
|
|
7629ac |
+ <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
|
|
|
7629ac |
+ </ind:textfilecontent54_object>
|
|
|
7629ac |
+
|
|
|
7629ac |
+</def-group>
|
|
|
7629ac |
diff --git a/linux_os/guide/system/auditing/auditd_configure_rules/directory_access_var_log_audit.rule b/linux_os/guide/system/auditing/auditd_configure_rules/directory_access_var_log_audit.rule
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..acf6fc6a0e
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/linux_os/guide/system/auditing/auditd_configure_rules/directory_access_var_log_audit.rule
|
|
|
7629ac |
@@ -0,0 +1,33 @@
|
|
|
7629ac |
+documentation_complete: true
|
|
|
7629ac |
+
|
|
|
7629ac |
+title: 'Record Access Events to Audit Log directory'
|
|
|
7629ac |
+
|
|
|
7629ac |
+description: |-
|
|
|
7629ac |
+ The audit system should collect access events to read audit log directory.
|
|
|
7629ac |
+ The following audit rule will assure that access to audit log directory are
|
|
|
7629ac |
+ collected.
|
|
|
7629ac |
+ -a always,exit -F dir=/var/log/audit/ -F perm=r -F auid>=1000 -F auid!=unset -F key=access-audit-trail
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>augenrules</tt>
|
|
|
7629ac |
+ program to read audit rules during daemon startup (the default), add the
|
|
|
7629ac |
+ rule to a file with suffix <tt>.rules</tt> in the directory
|
|
|
7629ac |
+ <tt>/etc/audit/rules.d</tt>.
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>auditctl</tt>
|
|
|
7629ac |
+ utility to read audit rules during daemon startup, add the rule to
|
|
|
7629ac |
+ <tt>/etc/audit/audit.rules</tt> file.
|
|
|
7629ac |
+
|
|
|
7629ac |
+rationale: |-
|
|
|
7629ac |
+ Attempts to read the logs should be recorded, suspicious access to audit log files could be an indicator of malicious activity on a system.
|
|
|
7629ac |
+ Auditing these events could serve as evidence of potential system compromise.'
|
|
|
7629ac |
+
|
|
|
7629ac |
+references:
|
|
|
7629ac |
+ ospp@rhel7: FAU_GEN.1.1.c
|
|
|
7629ac |
+
|
|
|
7629ac |
+severity: unknown
|
|
|
7629ac |
+
|
|
|
7629ac |
+ocil_clause: "no line is returned"
|
|
|
7629ac |
+
|
|
|
7629ac |
+ocil: |-
|
|
|
7629ac |
+ To determine if the system is configured to audit accesses to
|
|
|
7629ac |
+ /var/log/audit directory, run the following command:
|
|
|
7629ac |
+ $ sudo grep "dir=/var/log/audit" /etc/audit/audit.rules
|
|
|
7629ac |
+ If the system is configured to audit this activity, it will return a line.
|
|
|
7629ac |
diff --git a/rhel7/profiles/ospp42-draft.profile b/rhel7/profiles/ospp42-draft.profile
|
|
|
7629ac |
index 42c1e98e39..0a71eb16f6 100644
|
|
|
7629ac |
--- a/rhel7/profiles/ospp42-draft.profile
|
|
|
7629ac |
+++ b/rhel7/profiles/ospp42-draft.profile
|
|
|
7629ac |
@@ -139,6 +139,7 @@ selections:
|
|
|
7629ac |
- audit_rules_privileged_commands_sudo
|
|
|
7629ac |
- audit_rules_privileged_commands_su
|
|
|
7629ac |
- audit_rules_session_events
|
|
|
7629ac |
+ - directory_access_var_log_audit
|
|
|
7629ac |
- ensure_redhat_gpgkey_installed
|
|
|
7629ac |
- ensure_gpgcheck_globally_activated
|
|
|
7629ac |
- ensure_gpgcheck_never_disabled
|
|
|
7629ac |
diff --git a/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/auditctl_correct_rule.pass.sh b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/auditctl_correct_rule.pass.sh
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..e9b1d56af3
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/auditctl_correct_rule.pass.sh
|
|
|
7629ac |
@@ -0,0 +1,9 @@
|
|
|
7629ac |
+#!/bin/bash
|
|
|
7629ac |
+
|
|
|
7629ac |
+# profiles = xccdf_org.ssgproject.content_profile_ospp
|
|
|
7629ac |
+# remediation = none
|
|
|
7629ac |
+
|
|
|
7629ac |
+# Use auditctl in RHEL7
|
|
|
7629ac |
+sed -i "s%^ExecStartPost=.*%ExecStartPost=-/sbin/auditctl%" /usr/lib/systemd/system/auditd.service
|
|
|
7629ac |
+
|
|
|
7629ac |
+echo "-a always,exit -F dir=/var/log/audit/ -F perm=r -F auid>=1000 -F auid!=unset -F key=access-audit-trail" >> /etc/audit/audit.rules
|
|
|
7629ac |
diff --git a/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/auditctl_wrong_dir.fail.sh b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/auditctl_wrong_dir.fail.sh
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..1c68a3229b
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/auditctl_wrong_dir.fail.sh
|
|
|
7629ac |
@@ -0,0 +1,9 @@
|
|
|
7629ac |
+#!/bin/bash
|
|
|
7629ac |
+
|
|
|
7629ac |
+# profiles = xccdf_org.ssgproject.content_profile_ospp
|
|
|
7629ac |
+# remediation = none
|
|
|
7629ac |
+
|
|
|
7629ac |
+# Use auditctl in RHEL7
|
|
|
7629ac |
+sed -i "s%^ExecStartPost=.*%ExecStartPost=-/sbin/auditctl%" /usr/lib/systemd/system/auditd.service
|
|
|
7629ac |
+
|
|
|
7629ac |
+echo "-a always,exit -F dir=/var/log/auditd/ -F perm=r -F auid>=1000 -F auid!=unset -F key=access-audit-trail" >> /etc/audit/audit.rules
|
|
|
7629ac |
diff --git a/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_correct_rule.pass.sh b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_correct_rule.pass.sh
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..58ef8bc15f
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_correct_rule.pass.sh
|
|
|
7629ac |
@@ -0,0 +1,6 @@
|
|
|
7629ac |
+#!/bin/bash
|
|
|
7629ac |
+
|
|
|
7629ac |
+# profiles = xccdf_org.ssgproject.content_profile_ospp
|
|
|
7629ac |
+# remediation = none
|
|
|
7629ac |
+
|
|
|
7629ac |
+echo "-a always,exit -F dir=/var/log/audit/ -F perm=r -F auid>=1000 -F auid!=unset -F key=access-audit-trail" >> /etc/audit/rules.d/var_log_audit.rules
|
|
|
7629ac |
diff --git a/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_wrong_dir.fail.sh b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_wrong_dir.fail.sh
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..29f0f2d38e
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_wrong_dir.fail.sh
|
|
|
7629ac |
@@ -0,0 +1,6 @@
|
|
|
7629ac |
+#!/bin/bash
|
|
|
7629ac |
+
|
|
|
7629ac |
+# profiles = xccdf_org.ssgproject.content_profile_ospp
|
|
|
7629ac |
+# remediation = none
|
|
|
7629ac |
+
|
|
|
7629ac |
+echo "-a always,exit -F dir=/var/log/auditd/ -F perm=r -F auid>=1000 -F auid!=unset -F key=access-audit-trail" >> /etc/audit/rules.d/var_log_audit.rules
|
|
|
7629ac |
diff --git a/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_wrong_perm.fail.sh b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_wrong_perm.fail.sh
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..82eae1895d
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/tests/data/group_system/group_auditing/group_auditd_configure_rules/rule_directory_access_var_log_audit/augenrules_wrong_perm.fail.sh
|
|
|
7629ac |
@@ -0,0 +1,6 @@
|
|
|
7629ac |
+#!/bin/bash
|
|
|
7629ac |
+
|
|
|
7629ac |
+# profiles = xccdf_org.ssgproject.content_profile_ospp
|
|
|
7629ac |
+# remediation = none
|
|
|
7629ac |
+
|
|
|
7629ac |
+echo "-a always,exit -F dir=/var/log/audit/ -F perm=w -F auid>=1000 -F auid!=unset -F key=access-audit-trail" >> /etc/audit/rules.d/var_log_audit.rules
|