Dashboards

Security Dashboard

Description:

The security dashboard assumes /var/log/messages and /var/log/secure are being monitored. The associated query looks for things like “segfault” and “Failed password” and other things which may indicate an attack.

The second query looks for “Port scan detected” and relies on syslog messages sent from PSAD (Port Scan Automated Detection) running on a system. It analyzes iptables logs and alerts when a port scan is being run.

Taken together, these two queries and the dashboard can give a timeline of a potential attack taking place:

1.) Scans are run looking for open services (“Port scan detected”)
2.) Common SSH logins are attempted (“Failed password”)
3.) Failing that, the attacker finds a possibly-exploitable program and begins testing (“segfault”)
4.) If the attacker gets in, he might create a user for himself or delete one (“new user”)

Since /var/log/messages and /var/log/secure are present on nearly every Linux system, this dashboard (even without the PSAD query) can be used in many environments with little to no setup required.

Current Version

Last Release Date

December 15, 2014

Compatible With

  • Nagios Log Server

Project Files
Project Photos
Project Notes
Reviews (0) Add a Review
Add a Review

You must be logged in to submit a review.

Thank you for your review!

Your review has been submitted and is pending approval.

Recommend

To:


From:


Thank you for your recommendation!

Your recommendation has been sent.

Project Stats
Rating
0 (0)
Favorites
0
Views
16,097