System Accounting and Auditing

From linsec.ca

Jump to: navigation, search

Making sure your system is configured securely before making it live is very important, but one cannot take the view that once it is configured securely, the job is done. In fact, the job is just beginning! Once that system is "live", you need to pay attention to it, to make sure it is running smoothly and that nothing untowards is happening on, or to, it.

To that end, auditing your system periodically, or having optional tools do this for you, is the next logical step. There are a number of tools available that will help any user or sysadmin accomplish this. Some will come with any base OS, others may need to be compiled and installed from source, depending on the OS. There are a number of different types of accounting as well, and this section should identify most of them. In particular, attention should be paid to auditing logfiles, process accounting, connection accounting, filesystem accounting, and so forth.

Personal tools
Toolbox