Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Sun
[Top] [All Lists]

RE: BSM and syslog... why should I consider the first?

Subject: RE: BSM and syslog... why should I consider the first?
Date: Sat, 16 Jul 2005 10:24:29 -0500
Hi,
 
BSM and syslog are very different, as Robert has pointed out. BSM has been used 
by some to create host based Intrustion Detection Systems (See ASAXC, good luck 
finding it). Just wanted to add that you do not HAVE to use Sun's tools to view 
the audit trail. They do ship a tool, praudit, but I've found that it is very 
slow. You are probably better off doing what we've done, and write your own 
parser. They include the header files so you can determine the structure of the 
audit file and easily whip up some C code.
 
Good luck and I hope you enjoy BSM.

________________________________

From: Robert Escue [mailto:roescue@cox.net]
Sent: Fri 7/8/2005 5:06 AM
To: Simone Vernacchia
Cc: focus-sun@securityfocus.com
Subject: Re: BSM and syslog... why should I consider the first?



Simone Vernacchia wrote:

Hello everyone,

I'm working on a Security program for a large infrastructure.
I have to deal with Sun Solaris, and I was wondering why I should
consider logging via BSM and not syslog.
System admins have a good knowledge of syslog, and I can standardize
logging in different UNIX OSes easily if I use it.
Is there some breaking feature which could make me prefer BSM?
Is there a reason to use syslog and BSM?

Thanks in advance,
G0k





Simone,

BSM is auditing for Solaris, not logging. If you wanted your machine(s)
to be C2/EAL4 compliant and wanted to have a trail of what users did on
that machine, you would enable BSM. The detractors are increased CPU
utilization, preferably having a dedicated partition to write the audit
data to (depending on activity level it could be large) and the audit
trail can only be read using Sun's tools (except for Solaris 10 which
has other options).

Hope this helps.


Robert Escue
System Administrator




<Prev in Thread] Current Thread [Next in Thread>