![]() |
Typically a system administrator will create an initial AIDE database on a system after Avaya Experience Portal is installed. The administrator then sets up a cron job to reproduce a daily or weekly report depending on the system needs. The first AIDE database is a snapshot of the system in its normal state by which all subsequent updates and changes will be measured. This notifies you within, at most, 24 hours of when any file was changed, added, or removed. It also helps establishing an audit trail in the event your site is compromised.
For security reasons, it is a good practice to store the AIDE configuration file on a read-only removable media instead of the default location. If the system is comprised, intruders can not just read the AIDE configuration file and look for directories that are skipped for AIDE monitoring, but also can alter the URL of the output database in order to trick subsequent AIDE scans. For similar reasons, it may also be a good practice to store the AIDE’s output database on the read/write removable media, then subsequently copy the new database to a read-only media.
/etc/aide.conf is the default configuration file installed by the AIDE package.
/etc/aide.conf does the following:
Controls the default scanning and reporting rules.
Contains the run time configuration AIDE uses to initialize or check the AIDE database.
Determines whether and how AIDE should report a file or directory as having changed, and which attributes AIDE should consider when scanning.