4.2 Enable Auditing of Incoming Network Connections - AUE_SOCKCONNECT : cis

Information

The Solaris Audit service can be configured to record incoming network connections to any
listening service running on the system.

This recommendation will provide an audit trail that contains information related to
incoming network connections. While this functionality can be enabled using service-
specific mechanisms, using the Solaris Audit service provides a more centralized and
complete window into incoming network activity.

Solution

To enforce this setting, edit the /etc/security/audit_event file and add the cis audit
class to the following audit events-AUE_ACCEPT
AUE_CONNECT
AUE_SOCKACCEPT
AUE_SOCKCONNECT
AUE_inetd_connect

See Also

https://workbench.cisecurity.org/files/616

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 30b3572484758a1c9032edd426c316768830f8b55fab17ac8821b89a48f96ed8