14
Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen (New Mexico Institute of Mining and Technology) Mentor: David Kennel (DCS-1) Instructor: Andree Jacobson (NMC) 2011 Computer System, Cluster and Networking Summer Institute

Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Embed Size (px)

Citation preview

Page 1: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Cost of SecurityAuditing FocusMatthew Chambers (Michigan Technological University)Kevin Lopez (California State University, San Bernardino)Casey Mortensen (New Mexico Institute of Mining and Technology)

Mentor: David Kennel (DCS-1)Instructor: Andree Jacobson (NMC)

2011 Computer System, Cluster and Networking Summer Institute

Page 2: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Introduction

What is the audit daemon?

What purpose does auditd serve?

What is the cost of security?

Page 3: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Auditd

Kernel level service

Intrusion Detection System

Does not preventmalicious activity

Novell © - http://www.novell.com/documentation/sled10/pdfdoc/audit_sp1/audit_sp1.pdf

Page 4: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

The Benefits of Auditd

Increased security Monitor file activity Monitor syscall activity

Creates detailed logs User info, syscall used, timestamp, etc.

Robust search and filter implementations

Easy, manageable logging rotation solution

Page 5: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

The Drawbacks of Auditd

Performance degradation CPU interrupts Context Switching Logging

Only a detection system

Page 6: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Results (Small File I/O)

Page 7: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Results (Small File I/O)

Page 8: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Results (Intel MPI)

Page 9: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Results (Syscalls)

Page 10: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Hybrid Benchmark

Init

Calculate prime in range

Write to file

Write to file

Write to file

C HMOD

Read all files

Calculate prime in range

Calculate prime in range

Write to one file

Fork

CPython

BASH

Page 11: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Results (Hybrid)

Page 12: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

What to consider…

Scaling

Protection Measures (SE Linux)

NFS vs Audit Dispatcher

SSD and RAM performance

Page 13: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Conclusion

Performance Cost Non-CAPP rules CAPP Rules

Recommendation Minimal day to day impact Implement Auditing

Page 14: Cost of Security Auditing Focus Matthew Chambers (Michigan Technological University) Kevin Lopez (California State University, San Bernardino) Casey Mortensen

Questions?