Secure system administration
Page 6 of 6
Log and audit administration activities
Monitoring your administrator's activities will enable you to identify misuse of administrative privileges and respond appropriately.
Because misuse of administration accounts can have such a serious impact on your business, it’s vitally important to identify and try to stop any and all misuse as quickly as possible. The key to this is monitoring.
Monitoring your administrator's activities is essential. This will enable you to identify misuse of administrative privileges and respond appropriately.
Monitoring shows that you care about your system and will act as a deterrent for misuse. If an administrator account is compromised, monitoring will help you retrospectively discover what activities have happened on your systems.
Monitoring administration activity
There are different types of monitoring. Here, we describe two categories: automatic and manual.
Automatic
Automatic monitoring is conducted by computers. Rules are written, and a computer applies them to a feed of logging events. When a rule is triggered, an action can be carried out, such as alerting a person who can investigate and respond.
For example, you could define a rule that Tier 0 administrator accounts should not be used to sign in. If this is detected, a person can be alerted and investigate this activity.
Manual
Manual monitoring is conducted by members of staff. This will likely involve a person combing through lots of logging events, in an attempt to detect ‘abnormal’ activity.
For this to work, the analyst will need to understand what ‘normal’ looks like.
Manual monitoring can be used to understand and create new automated monitoring rules.
Investing in automation enables manual monitoring
Automatic monitoring can scale well, even with large amounts of logging data. But, automatic rules risk false positives and false negatives, unless they are constantly developed.
Automated monitoring should take the ‘grunt work’ away from a human analyst, so they can focus their efforts where human intuition is needed.
Security Operations Centre
Monitoring is often conducted from a Security Operations Centre (SOC). It’s important that system administration interfaces and activity are factored in to security operations. To find out more, read our SOC buyer’s guide.
Use your risk assessment and threat modelling to inform monitoring. This will help you identify the logging data you need to collect in order to detect misuse of administrator accounts.
Don’t do this in isolation. Work with your SOC analysts to create a common understanding.
When generating logs from your system administration activity, ask yourself questions to make sure you are collecting the data you need:
- Who carried out an action, when and from where?
- What was the action, and what did it do?
If a PAM solution has been implemented it’s likely that it can be configured to answer these questions. However, you should ensure that a link is made between the PAM solution and your SOC so that the logs can be acted upon.
Implementation guidance
- Drive monitoring from your risk and threat assessments. Use the output of risk and threat assessments to identify which administration interfaces may be targeted by an attacker. Use this to inform your logging and security monitoring strategy.
- Collect the right data. Consider what information you might need to support auditing and monitoring, then make sure to collect it.
- Define normal. Understand what intended system administration looks like. Use this to inform your security monitoring. This will be different for everyone.
- Work with security analysis. Security analysts need to understand how your system administration works. Otherwise, it will be difficult for them to identify suspicious behaviour.
- Test your monitoring. Run red and blue team exercises on your system administration interfaces, to check your monitoring is operating effectively.
Example Scenario A - Small Company
Small company uses SSH to connect to a front end web server, that hosts an information-only website.
In this scenario, the impact of compromise is restricted. It would allow an attacker to gain control of a front end web server which could lead to to a loss of reputation.
As a small company it is not possible to establish a fully functioning SOC. Nor is it financially viable to purchase one. Instead, they assign the role of analyst to a few employees, alongside their main roles. They don’t have a sophisticated system to carry out automatic analysis, so they rely on the analysts to perform manual analysis.
The web server that hosts the external content will raise an alarm each time an administrator logs in. This is in the form of an email and it contains details such as the credentials that were used and the IP address of the connection.
The analyst can review these emails in real time and contact administrators to ensure that their access is legitimate.
Example Scenario B - Large Company
A Critical National Infrastructure company uses a thick client to control a valve in their OT environment.
In this scenario, the impact of the administration interfaces being compromised is critical as the system provides an essential service to citizens.
As a large organisation with a significant revenue, this company is in a position to operate its own SOC. This SOC has 2 teams, one dedicated automatic and the other to manual monitoring.
The automatic team uses large batches of historic logs to define what normal operation looks like. From this, they establish rules that trigger alarms.
These alarms are investigated by the manual team. They are responsible for investigating any suspicious activity and taking action where appropriate. If necessary, they have can raise issues up to board level.
Blue team exercises are scheduled to be held at least once a year. After any significant system change, a red team exercise will be scheduled.