AIDE (Advanced Intrusion Detection Environment) is a free, open-source file integrity checker — conceptually the same job as Tripwire (snapshot a set of files, detect later changes), lighter-weight, and the one most current distributions package directly.
Install¶
sudo apt-get install aide # Debian/Ubuntu
sudo dnf install aide # RHEL/Fedora
Configuration: /etc/aide/aide.conf (or /etc/aide.conf)¶
Two parts: rule definitions (which file properties to check) and path selections (which rule applies to which paths).
# Rule definitions — combine attributes with +
Binlib = p+i+n+u+g+s+m+c+md5+sha256
ConfFiles = p+i+n+u+g+s+m+c+md5
LogFiles = p+i+n+u+g+S
# Path selections — rule then path, ! excludes
/bin Binlib
/sbin Binlib
/usr/bin Binlib
/usr/sbin Binlib
/etc ConfFiles
!/etc/mtab
/var/log LogFiles
p=permissions, i=inode, n=link count, u=owner, g=group, s=size, m=mtime, c=ctime, md5/sha256/sha512=hashes. Watching log directories for content hashes is usually pointless (they're supposed to grow) — the LogFiles example above checks permissions and size class rather than content hash for that reason.
Initialize the baseline database¶
sudo aideinit # on Debian/Ubuntu, wraps the steps below and installs a cron job
# or manually:
sudo aide --config /etc/aide/aide.conf --init
sudo mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
As with Tripwire, do this on a freshly built, hardened system — the database is only as trustworthy as the state it was taken from.
Run a check¶
sudo aide --config /etc/aide/aide.conf --check
Output lists added/removed/changed entries under Added entries, Removed entries, and Changed entries, each with the specific attributes that differ.
Update the database after a legitimate change¶
sudo aide --config /etc/aide/aide.conf --update
sudo mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
There is no interactive accept/reject like Tripwire's --update; review the check output first, confirm the changes are expected, then regenerate the whole database from current disk state.
Automate and alert¶
# /etc/cron.d/aide-check
30 3 * * * root /usr/bin/aide --config /etc/aide/aide.conf --check | mail -s "AIDE report: $(hostname)" [email protected]
Debian/Ubuntu's aideinit sets up a similar daily cron job under /etc/cron.daily/aide automatically.
Store the database off-host¶
If an attacker gets root, they can regenerate aide.db to match their changes and hide them entirely. Copy the database (and ideally the binary/config) to read-only or remote storage after each --init/--update, or sign it, so a compromised host can't quietly rewrite its own baseline. See gnupg for signing.