Andrew Mercer
on this page

AIDE (Advanced Intrusion Detection Environment) is a free, open-source file integrity checker — conceptually the same job as Tripwire (snapshot a set of files, detect later changes), lighter-weight, and the one most current distributions package directly.

Install

sudo apt-get install aide           # Debian/Ubuntu
sudo dnf install aide               # RHEL/Fedora

Configuration: /etc/aide/aide.conf (or /etc/aide.conf)

Two parts: rule definitions (which file properties to check) and path selections (which rule applies to which paths).

# Rule definitions — combine attributes with +
Binlib = p+i+n+u+g+s+m+c+md5+sha256
ConfFiles = p+i+n+u+g+s+m+c+md5
LogFiles = p+i+n+u+g+S

# Path selections — rule then path, ! excludes
/bin        Binlib
/sbin       Binlib
/usr/bin    Binlib
/usr/sbin   Binlib
/etc        ConfFiles
!/etc/mtab
/var/log    LogFiles

p=permissions, i=inode, n=link count, u=owner, g=group, s=size, m=mtime, c=ctime, md5/sha256/sha512=hashes. Watching log directories for content hashes is usually pointless (they're supposed to grow) — the LogFiles example above checks permissions and size class rather than content hash for that reason.

Initialize the baseline database

sudo aideinit                                    # on Debian/Ubuntu, wraps the steps below and installs a cron job
# or manually:
sudo aide --config /etc/aide/aide.conf --init
sudo mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db

As with Tripwire, do this on a freshly built, hardened system — the database is only as trustworthy as the state it was taken from.

Run a check

sudo aide --config /etc/aide/aide.conf --check

Output lists added/removed/changed entries under Added entries, Removed entries, and Changed entries, each with the specific attributes that differ.

Update the database after a legitimate change

sudo aide --config /etc/aide/aide.conf --update
sudo mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db

There is no interactive accept/reject like Tripwire's --update; review the check output first, confirm the changes are expected, then regenerate the whole database from current disk state.

Automate and alert

# /etc/cron.d/aide-check
30 3 * * *  root  /usr/bin/aide --config /etc/aide/aide.conf --check | mail -s "AIDE report: $(hostname)" [email protected]

Debian/Ubuntu's aideinit sets up a similar daily cron job under /etc/cron.daily/aide automatically.

Store the database off-host

If an attacker gets root, they can regenerate aide.db to match their changes and hide them entirely. Copy the database (and ideally the binary/config) to read-only or remote storage after each --init/--update, or sign it, so a compromised host can't quietly rewrite its own baseline. See gnupg for signing.