Re: SoC: Distributed Audit Daemon project



In message: <200705252004.38092.mail@xxxxxxxxxx>
Benjamin Lutz <mail@xxxxxxxxxx> writes:
: On Friday 25 May 2007 01:22:21 Alexey Mikhailov wrote:
: > [...]
: > 2. As I said before initial subject of this project was "Distributed
: > audit daemon". But after some discussions we had decided that this
: > project can be done in more general maner. We can perform distributed
: > logging for any user-space app.
: > [...]
:
: This sounds very similar to syslogd. Is it feasible to make dlogd a drop-in
: replacement for syslogd, at least from a syslog-using-program point of view?

I suspect that it is dealing with different data streams. syslog is
for programs sending text voluntarily. auditd is for pulling audit
trails out of the kernel for which the 'target' programs have no
knowledge that the audit trails are being generated, let alone anyway
to prevent it.

Warner
_______________________________________________
freebsd-hackers@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: SoC: Distributed Audit Daemon project
    ... This sounds very similar to syslogd. ... auditd is for pulling audit trails out of the kernel for which the 'target' programs have no knowledge that the audit trails are being generated, let alone anyway to prevent it. ... A distributed audit daemon wouldn't eliminate the need for local daemons ... syslogd for syslog, auditd for audit, Apache generating its own log files, ...
    (freebsd-hackers)
  • RE: [Full-disclosure] PCI Audit Logging
    ... rationale is to be able to detect attempted alterations of logs. ... then the audit log has questionable value as ... All key management activities should be logged and adequate information ... characteristics of audit trails are: ...
    (Full-Disclosure)
  • [Full-disclosure] PCI Audit Logging
    ... "Corporate policy and audit logging will be changed to include ... server where the card holder data is stored. ... All key management activities should be logged and adequate information ... The characteristics of audit trails are: ...
    (Full-Disclosure)