Linux kernel auditing: Architecture and principles
4
Usefulness of Audit subsystem
5
Components of Audit subsystem
6
User space component of Audit subsystem
7
Setting up audit system
8
Audit subsystem Tools
9
Configuring the audit daemon
10
Setting up audit rules
11
Basic audit rules
12
Watches on log and configuration files
13
Monitoring the system objects using system calls
14
Monitoring security configuration files
15
Filtering system call arguments
16
Audit subsystem - How does it works
17
An audit event record
Description:
Explore the Linux Kernel Audit Subsystem in this comprehensive conference talk by Vandana Salve from Prasme Systems. Gain insights into the architecture and principles of Linux kernel auditing, understanding its usefulness and components. Learn how to set up and configure the audit system, including the audit daemon and rules. Discover various audit subsystem tools and techniques for monitoring system objects, security configuration files, and filtering system call arguments. Delve into the inner workings of the audit subsystem and understand how audit event records are generated. This in-depth presentation provides a thorough overview of monitoring Linux systems using the Kernel Audit Subsystem, equipping you with valuable knowledge for enhancing system security and compliance.
Monitoring Linux Systems Using Kernel Audit Subsystem