Auditing
¡á trusted systemÀ¸·Î ÀüȯÀÌ µÇ¸é auditing ±â´ÉÀ» »ç¿ë °¡´É
¡á auditingÀ» ½ÃÀÛÇÏ·Á¸é sam(1m)¿¡¼ ½ÃÀÛ½ÃÅ°°Å³ª /etc/rc.config.d¿¡ ÀÖ´Â auditing fileÀ» ¾Æ·¡¿Í °°ÀÌ ¼öÁ¤
. . .
AUDITING=1
. . .
¡á audit¿¡ °ü·ÃµÈ ÀÛ¾÷À» sam(1m)À» ÀÌ¿ëÇÏ¿© ÇÒ ¼ö ÀÖÀ¸³ª ¾Æ·¡ÀÇ ¸í·ÉÀ¸·Îµµ ¼öÇà °¡´É
audsys(1m) auditing ½ÃÀÛ/Á¾·á
audusr(1m) audit ´ë»ó »ç¿ëÀÚ ¼³Á¤
audevent(1m) event ¶Ç´Â system callÀÇ Ãâ·Â ¹× »óÅ º¯°æ
audomon(1m) audit fileÀÇ overflow¸¦ °¨½ÃÇÏ´Â daemon
audisp(1m) audit record¸¦ Ãâ·Â
¡á audit log file °ü·Ã default Á¤º¸
primary log file = /.secure/etc/audfile1
primary log fileÀÇ switch size (AFS) = 5,000KB
º¸Á¶ log file = /.secure/etc/audfile2
º¸Á¶ log fileÀÇ switch size (AFS) = 1,000KB
monitorÀÇ check interval = 1 ºÐ
Çã¿ë °¡´ÉÇÑ ÃÖ¼ÒÇÑÀÇ file systemÀÇ free space (FSS) = 20%
°æ°í¸¦ º¸³»±â ½ÃÀÛÇÏ´Â log fileÀÇ »ç¿ë·® = 90%
¡á event typeÀº auditÀÌ ¼öÇàµÇ´Â ´ë»ó. ±âº»À¸·Î "
admin", "login" ±×¸®°í "moddac"°¡ ¼±ÅõÊ.
|