You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Linux中使用auditctl捕获chmod操作时记录进程名而非PID

解决auditctl记录触发chmod命令的父进程名问题

针对你遇到的进程终止后无法通过PID获取触发chmod的父进程名问题,提供以下三种实用方案:

方案1:在chmod别名中直接记录父进程名

既然你已经通过别名接管了chmod命令,可直接在别名逻辑中获取并记录父进程名,无需依赖auditctl事后查询:

假设你的chmod别名是bash函数,修改如下:

chmod() {
    # 获取触发chmod的父进程名
    PARENT_COMM=$(ps -o comm= -p $PPID)
    # 遍历要修改权限的文件,检查是否为受限文件
    for FILE in "${@:2}"; do
        if [[ "$FILE" == "/path/to/restricted/system/file" ]]; then
            echo "You cannot change permission of this file as this is system file"
            # 将拒绝事件及父进程信息写入系统日志
            logger -p auth.warning "Denied chmod on restricted file: $FILE | Parent process: $PARENT_COMM (PID: $PPID)"
            return 1
        fi
    done
    # 执行真实的chmod命令
    /bin/chmod "$@"
    # 将允许事件及父进程信息写入系统日志
    logger -p auth.info "Allowed chmod operation: $* | Parent process: $PARENT_COMM (PID: $PPID)"
}

之后可直接在系统日志(如/var/log/auth.log或/var/log/messages)中查看包含父进程名的审计记录。

方案2:调整auditctl规则,关联父进程审计日志

auditctl的SYSCALL日志已包含父进程PID(ppid字段),可通过以下步骤关联父进程名:

  1. 添加父进程启动监控规则
    执行以下命令,监控所有进程的启动事件,确保父进程的信息被记录:

    auditctl -a always,exit -F arch=b64 -S execve -k parent_process_exec
    

    该规则会记录所有进程的execve系统调用事件,包含进程PID、名称(comm)、可执行文件路径(exe)。

  2. 查询chmod事件对应的父进程
    当需要查找某条chmod审计记录的父进程名时,提取日志中的ppid值,执行以下命令:

    ausearch -k parent_process_exec -p <PPID_FROM_CHMOD_LOG>
    

    命令返回结果中的comm字段即为触发chmod的父进程名。

  3. 优化原chmod审计规则
    修改原有的chmod监控规则,过滤掉无父进程的系统进程:

    auditctl -a always,exit -F arch=b64 -S chmod -S fchmod -S fchmodat -F comm=chmod -k audit_time_perm_mod_export_delete -F ppid!=0
    

方案3:通过audit自定义事件记录父进程名

在chmod别名中调用auditctl发送自定义审计事件,直接将父进程名写入audit日志:

chmod() {
    PARENT_COMM=$(ps -o comm= -p $PPID)
    for FILE in "${@:2}"; do
        if [[ "$FILE" == "/path/to/restricted/system/file" ]]; then
            echo "You cannot change permission of this file as this is system file"
            # 发送自定义拒绝审计事件
            auditctl -m "Denied chmod on restricted file: $FILE | Parent process: $PARENT_COMM (PID: $PPID)"
            return 1
        fi
    done
    /bin/chmod "$@"
    # 发送自定义允许审计事件
    auditctl -m "Allowed chmod operation: $* | Parent process: $PARENT_COMM (PID: $PPID)"
}

自定义事件会以USER_MSG类型出现在audit日志中,直接包含父进程名,无需额外关联查询。

内容的提问来源于stack exchange,提问作者curious_techie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 10:02:11