温馨提示×

debian exploit如何写检测规则

小樊
40
2026-09-25 22:08:07
栏目: 智能运维

写 Debian(或 Linux 通用)exploit 检测规则,通常取决于你要在哪一层检测:

  • IDS / IPS(Suricata、Snort):检测利用流量
  • HIDS(Wazuh、Osquery、Auditd):检测本地利用行为
  • YARA / 文件扫描:检测 exploit 样本
  • 日志检测(syslog、auth.log):检测成功利用痕迹

下面按常见场景给你可直接改用的模板。


一、Suricata / Snort 规则(网络层)

1. 检测已知 CVE exploit 请求(如 sudo CVE-2021-3156)

alert tcp any any -> any 22 ( \
    msg:"Possible sudo heap overflow exploit (CVE-2021-3156)"; \
    flow:to_server; \
    content:"sudoedit"; \
    content:"-s"; \
    content:"\\"; \
    threshold:type limit, track by_src, count 1, seconds 60; \
    sid:100001; rev:1; \
)

2. 检测 exploit 扫描行为

alert tcp any any -> $HOME_NET any ( \
    msg:"Exploit scanning detected"; \
    flow:to_server; \
    content:"/etc/passwd"; \
    nocase; \
    sid:100002; rev:1; \
)

二、Wazuh / Auditd(主机层)

1. 检测提权 exploit 执行

<rule id="100100" level="12">
  <if_group>syscall</if_group>
  <match>execve</match>
  <match>/tmp/exploit</match>
  <description>Possible exploit execution</description>
</rule>

2. Auditd 规则(监控 exploit 常用路径)

-a always,exit -F path=/tmp -F perm=x -F auid>=1000 -k exploit_exec

三、Osquery 检测(运行时)

检测异常 SUID 文件(常见 exploit 载体)

SELECT * FROM suid_bin
WHERE path LIKE '/tmp/%'
   OR path LIKE '/dev/shm/%';

检测 CVE 影响的包版本

SELECT name, version FROM deb_packages
WHERE name = 'sudo'
  AND version < '1.8.27-1+deb10u3';

四、YARA 规则(样本层)

rule Debian_Exploit_Sample {
    meta:
        author = "you"
        description = "Detect known Debian exploit"
    strings:
        $a = "/etc/shadow" ascii
        $b = "CVE-2021-3156" ascii
    condition:
        $a and $b
}

五、日志检测(auth.log / syslog)

grep -E "authentication failure|sudo:.*NOT" /var/log/auth.log

Wazuh 示例:

<rule id="100200" level="10">
  <match>sudo:.*NOT in sudoers</match>
  <description>Possible privilege escalation attempt</description>
</rule>

六、写规则的关键思路(通用)

  1. 明确 CVE / 利用方式
  2. 选检测点
    • 网络?主机?文件?日志?
  3. 找稳定特征
    • 特定参数
    • 固定路径
    • 特定系统调用
  4. 避免误报
    • 加白名单
    • 限制用户 / IP

如果你能告诉我:

  • 具体 Debian 版本
  • 针对 哪个 CVE / exploit
  • 想用在 Suricata / Wazuh / YARA / 日志

我可以直接帮你写精准规则。

0 踩