1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59
|
documentation_complete: true
title: 'Configure auditing of unsuccessful permission changes'
{{% set file_contents_audit_perm_change_failed =
"## Unsuccessful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid>=" ~ uid_min ~ " -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid>=" ~ uid_min ~ " -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid>=" ~ uid_min ~ " -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid>=" ~ uid_min ~ " -F auid!=unset -F key=unsuccessful-perm-change" %}}
description: |-
Ensure that unsuccessful attempts to change file or directory permissions are audited.
The following rules configure audit as described above:
<pre>{{{ file_contents_audit_perm_change_failed|indent }}} </pre>
Load new Audit rules into kernel by running:
<pre>augenrules --load</pre>
Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are alligned with your needs.
rationale: |-
Unsuccessful attempts to change permissions of files or directories might be signs of malicious activity. Having such events audited helps in monitoring and investigation of such activities.
severity: medium
# on RHEL9+ there are rules which cover particular hardware architectures
# so do not apply this rule but apply the specific one instead
{{% if product in ["rhel9", "rhel10"] %}}
platforms:
- not aarch64_arch and not ppc64le_arch
{{% endif %}}
identifiers:
cce@rhel8: CCE-82837-6
cce@rhel9: CCE-83676-7
cce@rhel10: CCE-86610-3
references:
nist: AU-2(a)
ospp: FAU_GEN.1.1.c
srg: SRG-OS-000462-GPOS-00206,SRG-OS-000463-GPOS-00207,SRG-OS-000465-GPOS-00209,SRG-OS-000474-GPOS-00219,SRG-OS-000475-GPOS-00220,SRG-OS-000466-GPOS-00210,SRG-OS-000064-GPOS-00033
ocil_clause: 'the file does not exist or the content differs'
ocil: |-
To verify that the <tt>Audit</tt> is correctly configured according to recommended rules, check the content of the file with the following command:
<pre>cat /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules</pre>
The output has to be exactly as follows:
<pre>{{{ file_contents_audit_perm_change_failed|indent }}} </pre>
template:
name: audit_file_contents
vars:
filepath: /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules
contents: |-
{{{ file_contents_audit_perm_change_failed|indent(12) }}}
|