Automated security checks on Sidewinder7 firewall


 
Thread Tools Search this Thread
Top Forums UNIX for Advanced & Expert Users Automated security checks on Sidewinder7 firewall
# 1  
Old 12-15-2011
Automated security checks on Sidewinder7 firewall

I have recently been tasked to create a script that will daily check our firewalls for any security issues that might have happened. I am not very strong with Unix so I need a lot of help and dont know where to start.

Some things I have thought of so far is I want to search the audit.raw files for any occurrence of an admin account being changed. Also want to look for DNS lookups or port 80 GetRequests that are over 64k in size.

I was thinking i could run the script in a cronjob. Is that the best way?

My bosses would also like some kind of output that they can look at and understand.

I am sure there are a lot more things I should be looking for. Has anyone done something like this already or know a good place for me to start researching commands for this kind of task? Thank you in advance for any help you can offer.

Last edited by soccerfan; 12-15-2011 at 05:52 AM..
Login or Register to Ask a Question

Previous Thread | Next Thread

5 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Daily Checks

Hey Guys, I'm seeking some assistance in getting this script to run as a cron job for the user oracle.. the script is basically to perform 2 ADRCI checks... see the script below... i'm getting the following error: /export/home/oracle/Daily_Checks/ADRCI_Daily_Checks.sh: syntax error at line 16:... (7 Replies)
Discussion started by: Racegod
7 Replies

2. Cybersecurity

Firewall bypass or stepping stone security question

Hi, I really do not know how to describe this problem; but, I think it's a firewall issue. My Distro is Slackware 12.0 (somewhat updated). My company firewall uses Netfilter and the e-mail server uses Sendmail. Let's say the firewall's Ext IP = A and Internal DMZ IP = B. The firewall's... (0 Replies)
Discussion started by: cc_ew
0 Replies

3. AIX

Pre-checks

AIX Guys!!! What pre-checks would you do on a 5.3 server before TL/SP/APAR installation? Bala (2 Replies)
Discussion started by: balaji_prk
2 Replies

4. UNIX for Advanced & Expert Users

Doing Checks on a file

I have a process that I am trying to provide a solution for and have hit a brick wall and would like some pointers in the right direction. Basically on a daily basis a report is automatically generated in a CSV format (FIRST.CSV) which includes codes and amounts in the following format: ... (6 Replies)
Discussion started by: SAMZ
6 Replies

5. UNIX for Dummies Questions & Answers

Security checks needed and at what frequency

hi, what are the Security checks need to be performed and at what frequency ? thanks (1 Reply)
Discussion started by: Far
1 Replies
Login or Register to Ask a Question
DAILY(5)						      BSD File Formats Manual							  DAILY(5)

NAME
daily, daily.conf -- daily maintenance DESCRIPTION
The /etc/daily script is run, by default, every night on a NetBSD system. The /etc/daily.conf file specifies which of the standard daily services are performed. The variables described below can be set to ``YES'' or ``NO'' in the /etc/daily.conf file. Most default to ``YES'', but not all. Check the /etc/defaults/daily.conf file if you are in doubt. (Note that you should never edit /etc/defaults/daily.conf directly, as it is often replaced during system upgrades.) find_core This runs find(1) over the entire local filesystem, looking for core files. run_msgs This runs msgs(1) with the -c argument. expire_news This runs the /etc/expire.news script. purge_accounting This ages accounting files in /var/account. run_calendar This runs calendar(1) with the -a argument. check_disks This uses the df(1) and dump(8) to give disk status, and also reports failed raid(4) components. show_remote_fs In check_disks, show remote file systems, which are not reported on by default. check_mailq This runs mailq(1). check_network This runs netstat(1) with the -i argument, and also checks the rwhod(8) database, and runs ruptime(1) if there are hosts in /var/rwho. full_netstat By default, check_network outputs a summarized version of the netstat(1) report. If a full version of the output run with the -inv options is desired, set this variable. run_fsck This runs fsck(8) with the -n option. run_rdist This runs rdist(1) with /etc/Distfile. run_security This runs the /etc/security script looking for possible security problems with the system. run_skeyaudit Runs the skeyaudit(1) program to check the S/Key database and informs users of S/Keys that are about to expire. run_makemandb If the /etc/man.conf file exists, runs the makemandb(8) utility to update the man.db database for use by apropos(1). fetch_pkg_vulnerabilities Refreshes the local database of package vulnerabilities. See the settings in security.conf(5) for details on the actual package checks. The variables described below can be set to modify the tests: find_core_ignore_fstypes Lists filesystem types to ignore during the find_core phase. Prefixing the type with a '!' inverts the match. For example, 'procfs !local' will ignore 'procfs' type filesystems and filesystems that are not 'local'. find_core_ignore_paths Lists paths to ignore during the find_core phase. For example, '/export' will not descend into any directories under the '/export' hierarchy. This, on a file server, allows to skip user data while still scanning system files. run_fsck_flags Extra options to be passed to fsck(8) if run_fsck is enabled. send_empty_security If set, the report generated by the run_security phase will always be sent, even if it is empty. pkgdb_dir DEPRECATED. Please set PKGDB_DIR in pkg_install.conf(5) instead. If defined, points to the location of the packages database. Defaults to /var/db/pkg. FILES
/etc/daily daily maintenance script /etc/daily.conf daily maintenance configuration /etc/defaults/daily.conf default settings, overridden by /etc/daily.conf /etc/daily.local local site additions to /etc/daily SEE ALSO
monthly(5), security.conf(5), weekly(5) HISTORY
The /etc/daily.conf file appeared in NetBSD 1.3. BSD
July 30, 2012 BSD