ホストベースのセキュリティと監査

AIDE によるファイル整合性監視と、auditd による低レベルなシステム監査を通じて、ホストのセキュリティを強化します。システムログを解析し、ブルートフォース攻撃や特権昇格を検知する方法を学びます。

Cybersecurity EngineerサイバーセキュリティHydraKali Linux

💡 このチュートリアルは英語版からAIによって翻訳されています。原文を確認するには、 ここをクリックしてください

はじめに

ホストベースのセキュリティと監査では、Linux host から security evidence を生成し解釈する方法を学びます。3 個の guided lab で AIDE file integrity、auditd event tracking、authentication log analysis を扱い、最後の challenge で simulated insider access と file tampering を調査します。

isolated Ubuntu 22.04 VM で prepared sensitive directory、sample log、security event を使います。baseline の trust/scope、無差別 logging ではない targeted audit、すべての変更を attack と決めつけない evidence-based conclusion を重視します。

学習内容

  • AIDE の監視 path を設定し、cryptographic known-good database を初期化
  • integrity baseline を有効化・保護し、AIDE report の added/removed/changed file を区別
  • auditd の動作確認と、file/directory access 用 key 付き auditctl watch の作成
  • ausearch で event を path、command、executable、login identity、effective user と関連付け
  • authentication log から failed SSH attempt を filter/count
  • sudo command を抽出し、grep、awk、sort、uniq pipeline で host evidence を作成
  • AIDE report と audit record から simulated unauthorized reader と modified file を特定

このコースの対象者

host telemetry と integrity monitoring を実践したい SOC 学習者、Linux administrator、Security Analyst、Incident Responder 向けです。基本 Linux administration を理解し、privileged operation で evidence を調査できる人に適します。

前提知識: Linux shell pipeline、file/permission、sudo、systemd service check、authentication log の基礎。AIDE/auditd 経験は不要です。

学習環境: ブラウザー Ubuntu 22.04 VM で行う 4 個の独立 activity(3 guided lab、1 challenge)。AIDE、auditd、sensitive practice path、sample auth.log/syslog、simulated access/tampering event が用意されています。

よくある質問

AIDE は unauthorized change を防止しますか?

いいえ。current file と trusted baseline の差を報告しますが、write を阻止せず malicious かも判定しません。analyst が baseline を検証し結果を解釈します。

auditd rule は永続化されますか?

course は auditctl で immediate runtime watch を適用し key で検索します。/etc/audit/rules.d による persistence は扱わず、production deployment は対象外です。

challenge は実在 insider や production server を扱いますか?

いいえ。disposable VM の /opt/secure_data に verifier が access/tampering を simulation します。audit evidence から executable、AIDE report から changed file を特定します。

system log や external platform を用意する必要がありますか?

不要です。sample authentication/system log は local にあり、auditd event も VM 内で生成されます。SIEM や external account なしで command-line analysis を行います。

講師

labby
Labby
Labby is the LabEx teacher.