Discussion:
anom messages
Maupertuis Philippe
2018-05-24 15:06:11 UTC
Permalink
Hi,
The redhat security guide in annex B2 reads :
All Audit event types prepended with ANOM are intended to be processed by an intrusion detection program.
All Audit event types prepended with RESP are intended responses of an intrusion detection system in case it detects malicious activity on the system.

Can you point me towards an intrusion detection program able to manage these audit records.


Thanks
Philippe

!!!*************************************************************************************
"Ce message et les pi?ces jointes sont confidentiels et r?serv?s ? l'usage exclusif de ses destinataires. Il peut ?galement ?tre prot?g? par le secret professionnel. Si vous recevez ce message par erreur, merci d'en avertir imm?diatement l'exp?diteur et de le d?truire. L'int?grit? du message ne pouvant ?tre assur?e sur Internet, la responsabilit? de Worldline ne pourra ?tre recherch?e quant au contenu de ce message. Bien que les meilleurs efforts soient faits pour maintenir cette transmission exempte de tout virus, l'exp?diteur ne donne aucune garantie ? cet ?gard et sa responsabilit? ne saurait ?tre recherch?e pour tout dommage r?sultant d'un virus transmis.

This e-mail and the documents attached are confidential and intended solely for the addressee; it may also be privileged. If you receive this e-mail in error, please notify the sender immediately and destroy it. As its integrity cannot be secured on the Internet, the Worldline liability cannot be triggered for the message content. Although the sender endeavours to maintain a computer virus-free network, the sender does not warrant that this transmission is virus-free and will not be liable for any damages resulting from any virus transmitted.!!!"
Steve Grubb
2018-05-24 16:35:18 UTC
Permalink
Hello,
Post by Maupertuis Philippe
All Audit event types prepended with ANOM are intended to be processed by
an intrusion detection program. All Audit event types prepended with RESP
are intended responses of an intrusion detection system in case it detects
malicious activity on the system.
Can you point me towards an intrusion detection program able to manage these audit records.
It is in development but not ready to merge into the audit-userspace repo.
This is why I added some more event types in this area a couple months ago.
It is targeted for the audit-3.1 release along with a bunch of new audit
rules to assist in its job. Audit 3.1 should be late summer or fall of this
year.

-Steve

Continue reading on narkive:
Loading...