ホストベースのセキュリティと監査では、Linux host から security evidence を生成し解釈する方法を学びます。3 個の guided lab で AIDE file integrity、auditd event tracking、authentication log analysis を扱い、最後の challenge で simulated insider access と file tampering を調査します。
isolated Ubuntu 22.04 VM で prepared sensitive directory、sample log、security event を使います。baseline の trust/scope、無差別 logging ではない targeted audit、すべての変更を attack と決めつけない evidence-based conclusion を重視します。
学習内容
- AIDE の監視 path を設定し、cryptographic known-good database を初期化
- integrity baseline を有効化・保護し、AIDE report の added/removed/changed file を区別
- auditd の動作確認と、file/directory access 用 key 付き auditctl watch の作成
- ausearch で event を path、command、executable、login identity、effective user と関連付け
- authentication log から failed SSH attempt を filter/count
- sudo command を抽出し、grep、awk、sort、uniq pipeline で host evidence を作成
- AIDE report と audit record から simulated unauthorized reader と modified file を特定
このコースの対象者
host telemetry と integrity monitoring を実践したい SOC 学習者、Linux administrator、Security Analyst、Incident Responder 向けです。基本 Linux administration を理解し、privileged operation で evidence を調査できる人に適します。
前提知識: Linux shell pipeline、file/permission、sudo、systemd service check、authentication log の基礎。AIDE/auditd 経験は不要です。
学習環境: ブラウザー Ubuntu 22.04 VM で行う 4 個の独立 activity(3 guided lab、1 challenge)。AIDE、auditd、sensitive practice path、sample auth.log/syslog、simulated access/tampering event が用意されています。
よくある質問
AIDE は unauthorized change を防止しますか?
いいえ。current file と trusted baseline の差を報告しますが、write を阻止せず malicious かも判定しません。analyst が baseline を検証し結果を解釈します。
auditd rule は永続化されますか?
course は auditctl で immediate runtime watch を適用し key で検索します。/etc/audit/rules.d による persistence は扱わず、production deployment は対象外です。
challenge は実在 insider や production server を扱いますか?
いいえ。disposable VM の /opt/secure_data に verifier が access/tampering を simulation します。audit evidence から executable、AIDE report から changed file を特定します。
system log や external platform を用意する必要がありますか?
不要です。sample authentication/system log は local にあり、auditd event も VM 内で生成されます。SIEM や external account なしで command-line analysis を行います。





