课程: Ubuntu Linux: Operating System Basics

今天就学习课程吧!

今天就开通帐号,24,700 门业界名师课程任您挑!

Monitor security and audit the system

Monitor security and audit the system

- [Instructor] It's good practice to keep an eye on security events on your systems, and to conduct periodic audits. In this video, we'll take a look at a few things to keep an eye on fairly regularly, to help protect your systems from security threats. The first, and one of the most obvious places to watch, is the auth.log, or security log on the system. It holds information sent by services having to do with a system's security. SSH login attempts, users making use of sudo, and so on. Here on Ubuntu, the log can be found in /var/log/auth.log. Let's use sudo for something here, and see what that looks like in the log. I'll just write sudo ls here, and type in my password, and then I'll take a look at the log again. Right here is my user's usage of sudo. It can see the username that called sudo, which terminal it was on, what the current working directory was where the sudo command was used, and the command that was invoked with sudo. Any activity done with sudo will be logged here…

内容