18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 19: Auditing and Reporting<br />

Overview <strong>of</strong> the audit process<br />

Overview <strong>of</strong> the<br />

audit process<br />

532<br />

Figure 220: The audit<br />

flow<br />

Monitoring, auditing, reporting, and attack and system event responses are<br />

closely related pieces <strong>of</strong> the audit process. They function together to provide<br />

information to you about the activity on your <strong>Sidewinder</strong> <strong>G2</strong>. On the <strong>Sidewinder</strong><br />

<strong>G2</strong>, you can monitor the status <strong>of</strong> various processes in real time, view stored<br />

audit information, generate detailed reports, and have <strong>Sidewinder</strong> <strong>G2</strong> respond<br />

to audit events by alerting administrators and ignoring hosts sending malicious<br />

packets. The diagram below demonstrates how these pieces are related in the<br />

audit flow.<br />

Monitoring<br />

Using the Admin Console,<br />

you can monitor <strong>Sidewinder</strong><br />

<strong>G2</strong> activity and status in<br />

real time using the dashboard.<br />

Auditing<br />

auditd reads /dev/audit<br />

and places the<br />

information into<br />

audit.raw.<br />

This is the recorded<br />

audit stream. This is<br />

now "history" and<br />

contains everything that<br />

might be worth viewing.<br />

Reporting<br />

programs kernel<br />

live audit stream<br />

aka /dev/audit.....<br />

auditd<br />

/var/log/audit.raw<br />

auditdbd<br />

auditdb<br />

auditbotd<br />

auditbotd has a threshold<br />

and can trigger a response<br />

(see Chapter 20).<br />

Using the Admin Console,<br />

you can filter and view<br />

audit information.<br />

This is an SQL database <strong>of</strong><br />

information maintained by<br />

auditdbd. It contains all<br />

relevant audit information.<br />

Using <strong>Sidewinder</strong> <strong>G2</strong> Security Reporter,<br />

the Admin Console, or a third-party tool,<br />

you can generate detailed, easy-to-read<br />

reports.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!