-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SONiC Security Auditing HLD #1713
base: master
Are you sure you want to change the base?
Conversation
fabe961
to
f8391bf
Compare
Signed-off-by: Mai Bui <[email protected]>
dea4ed5
to
f67c824
Compare
Signed-off-by: Mai Bui <[email protected]>
community review recording https://zoom.us/rec/share/I2O2drYuFPNLFyWGPanI_rQ7qPIOkyfa9yNyJSON7BxDbKWcshSltjHwfUueU_tN.EySn3jaIk96H4zXA |
Signed-off-by: Mai Bui <[email protected]>
Signed-off-by: Mai Bui <[email protected]>
Signed-off-by: Mai Bui <[email protected]>
Signed-off-by: Mai Bui <[email protected]>
Signed-off-by: Mai Bui <[email protected]>
According to Sonic team and community's feedback, addressed and added some additional topics to the HLD
|
Signed-off-by: Mai Bui <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Signed-off-by: Mai Bui <[email protected]>
Signed-off-by: Mai Bui <[email protected]>
doc/audit/security_auditing_HLD.md
Outdated
@@ -37,7 +37,7 @@ | |||
## List of Tables | |||
* [Table 1: Revision](#table-1-revision) | |||
* [Table 2: Audit Rules Review](#table-2-audit-rules-review) | |||
* [Table 3: Unit Test Cases](#table-3-unit-test-cases) | |||
* [Table 3: Unt Test Cases](#table-3-unit-test-cases) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
typo: Unt #Closed
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed
doc/audit/security_auditing_HLD.md
Outdated
] | ||
} | ||
] | ||
"critical_files": "enabled", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For ConfigDB, the word convention is enable/disable
For StateDB, the word convention is enabled/disabled. #Closed
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed, thanks!
Signed-off-by: Mai Bui <[email protected]>
@liuh-80 @Yarden-Z @xincunli-sonic @venkatmahalingam @yxieca @prsunny @lguohan @StormLiangMS could you please help review the HLD? thanks |
This reverts commit 9750acb.
Signed-off-by: Mai Bui <[email protected]>
Signed-off-by: Mai Bui <[email protected]>
b59f532
@reviewers, would you please help to review this security feature? Thanks. |
Signed-off-by: Mai Bui <[email protected]>
PRs are not merged yet, move to backlog |
This design aims to enhance the auditing capabilities within SONiC operating system using audit daemon (auditd). Auditing is the process of recording and analyzing the events that occur on the device. Auditing can help to detect unauthorized access, configuration changes, malicious activity, or system errors. Auditing can also provide evidence for forensic investigations, compliance audits, or incident response.