8.1.11 Collect Unsuccessful Unauthorized Access Attempts to Files- '32bit EPERM'

Information

Monitor for unsuccessful attempts to access files. The parameters below are associated
with system calls that control creation (creat), opening (open, openat) and truncation
(truncate, ftruncate) of files. An audit log record will only be written if the user is a non-
privileged user (auid > = 500), is not a Daemon event (auid=4294967295) and if the system
call returned EACCES (permission denied to the file) or EPERM (some other permanent
error associated with the specific system call). All audit records will be tagged with the
identifier 'access.'

*Rationale*

Failed attempts to open, create or truncate files could be an indication that an individual or
process is trying to gain unauthorized access to the system.

Solution

For 64 bit systems, add the following lines to the /etc/audit/audit.rules file.
-a always,exit -F arch=b64 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EACCES -F auid>=500 -F auid!=4294967295 -k access
-a always,exit -F arch=b32 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EACCES -F auid>=500 -F auid!=4294967295 -k access
-a always,exit -F arch=b64 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EPERM -F auid>=500 -F auid!=4294967295 -k access
-a always,exit -F arch=b32 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EPERM -F auid>=500 -F auid!=4294967295 -k access

# Execute the following command to restart auditd
# pkill -HUP -P 1 auditd

For 32 bit systems, add the following lines to the /etc/audit/audit.rules file.
-a always,exit -F arch=b32 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EACCES -F auid>=500 -F auid!=4294967295 -k access
-a always,exit -F arch=b32 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EPERM -F auid>=500 -F auid!=4294967295 -k access

# Execute the following command to restart auditd
# pkill -HUP -P 1 auditd

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 5a8e509480281efde448c3c4eff0f845913c899a82de74cfbdffdd5efad1b839