8.3.1 Install AIDE

Information

In some installations, AIDE is not installed automatically.

*Rationale*

Install AIDE to make use of the file integrity features to monitor critical files for changes
that could affect the security of the system.

Solution

Install AIDE-

# apt-get install aide

Initialize AIDE-# aideinit
# cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db

Note- The prelinking feature can interfere with AIDE because it alters binaries to speed up
their start up times. Run /usr/sbin/prelink -ua to restore the binaries to their prelinked
state, thus avoiding false positives from AIDE.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), CSCv6|2.2

Plugin: Unix

Control ID: 37c22339c8a311108c3dee278f4b4e95895a37d283f61605de8a80c8da246098