8.3.1 Install AIDE

Information

In some installations, AIDE is not installed automatically. Install AIDE to make use of the file integrity features to monitor critical files for changes that could affect the security of the system.

Solution

Install AIDE- # apt-get install aide Initialize AIDE- # aideinit# cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db Note- The prelinking feature can interfere with AIDE because it alters binaries to speed up their start up times. Run /usr/sbin/prelink -ua to restore the binaries to their prelinked state, thus avoiding false positives from AIDE.

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), CSCv6|2.2

Plugin: Unix

Control ID: db217007dbdc89c52e99492abdb1bf9a7291edf91ba9093bc9d4ea90cc935e94