Security Audit
Abstract: Auditing the security of an
individual host and LAN is a necessary activity. This
lecture describes the components of a security policy and how to
set up a platform for conducting this audit, and the typical
structure of a final report.
- Educational Objectives
- Security Audit
- Lab Experiment
- Acknowledgements
- References
- Learn to audit Unix systems.
Security Audit
Print the slides, and read them! There are several Required Readings.
None.
The slides are based on a course taught by Farmer and Venema.
- Prabhaker Mateti, Security Audit, July 2000, [PowerPoint
slides].
- Lance Spitzner, "Auditing Your Firewall Setup," March, 2000. http://www.enteract.com/~lspitz/
audit.html. Required Reading.
- Henderson Group, "How to Audit Windows NT
Security," 10/01/97, http://home.us.net/~stu/
ntsec1.html Recommended Reading.
-
Dan Farmer, and Wietse Venema, "Improving the
Security of Your Site by Breaking Into it," [Local
copy .html] Required Reading.
- Auditors Checklists and Other Audit Information, http://all.net/books/audit/top.html
Recommended Reading.
- Dan Farmer, and Wietse Venema, "An Internet Security Audit for
fish.com computing network," 1996, [Local copy
.ps]. Required Reading.
- P. Holbrook, J. Reynolds (Editors), "RFC 1244, Site Security
Handbook," www.cis.ohio-state.edu/
htbin/rfc/ rfc1244.html Reference.