使用 OpenSCAP 确保系统安全

SUSE Multi-Linux Manager使用OpenSCAP对客户端进行审计。 它允许您为任何客户端调度和查看合规性扫描。

1. 关于 SCAP

安全内容自动化协议(SCAP)是基于社区思想的可互操作规范的综合。 这是由国家标准与技术研究院(NIST)维护的一系列规范,用于维护企业系统的系统安全。

SCAP的创建旨在提供维护系统安全的标准化方法,所使用的标准不断变化,以满足社区和企业的需求。 新规范由NIST的SCAP发布周期管理,以提供一致和可重复的修订工作流程。 有关更多信息,请参见:

SUSE Multi-Linux Manager使用OpenSCAP来实施SCAP规范。 OpenSCAP是一个审计工具,利用可扩展配置检查清单描述格式(XCCDF)。 XCCDF是一种表达检查清单内容的标准方式,并定义安全检查清单。 它还与其他规范结合,如通用平台枚举(CPE)、通用配置枚举(CCE)和开放漏洞与评估语言(OVAL),创建一个可以被SCAP验证产品处理的SCAP表达的检查清单。

OpenSCAP通过使用SUSE安全团队生成的内容来验证补丁的存在。 OpenSCAP 检查系统安全配置设置,并通过基于标准和规范的规则检测系统是否存在被入侵的迹象。 有关SUSE安全团队的更多信息,请参见 https://www.suse.com/support/security.。

2. 为 SCAP 扫描准备客户端

在开始之前,需要为客户端系统的 SCAP 扫描做好准备。

OpenSCAP 审计在使用 SSH 联系方法的 Salt 客户端上不可用。

扫描客户端可能会消耗被扫描客户端的大量内存和计算能力。 对于Red Hat客户端,请确保每个要扫描的客户端至少有2 GB的可用RAM。

在开始之前,请在客户端上安装OpenSCAP扫描器和SCAP安全指南(内容)软件包。 根据操作系统,这些软件包要么包含在基础操作系统中,要么包含在SUSE Multi-Linux Manager客户端工具中。

下表列出了所需的软件包:

Table 1. OpenSCAP 软件包
操作系统 扫描程序 内容

SLES

openscap-utils

scap-security-guide

openSUSE

openscap-utils

scap-security-guide

RHEL

openscap-utils

scap-security-guide-redhat

CentOS

openscap-utils

scap-security-guide-redhat

Oracle Linux

openscap-utils

scap-security-guide-redhat

Ubuntu

libopenscap8

scap-security-guide-ubuntu

Debian

libopenscap8

scap-security-guide-debian

RHEL 7 及兼容系统提供了一个 scap-security-guide 软件包,其中包含过时的内容。 建议您使用在 SUSE Multi-Linux Manager 客户端工具中找到的 scap-security-guide-redhat 软件包。

SUSE 为不同的 openscap 控制文件提供了 scap-security-guide 软件包。 在 scap-security-guide 的当前版本中,SUSE 支持以下控制文件:

  • 适用于 SUSE Linux Enterprise Server 12 和 15 的 DISA STIG 控制文件

  • 适用于 SUSE Linux Enterprise Server 12 和 15 的 ANSSI-BP-028 控制文件

  • 适用于 SUSE Linux Enterprise Server 12 和 15 的 PCI-DSS 控制文件

  • 适用于 SUSE Linux Enterprise Server 15 的 HIPAA 控制文件

  • SUSE Linux Enterprise Server for SAP Applications 15 的公有云映像安全强化

  • SUSE Linux Enterprise 15 的公有云安全强化

  • SLE 12 和 15 的标准系统安全性配置文件

对于非-SUSE 操作系统,包含的控制文件由社区提供。 它们不被 SUSE 官方支持。

3. OpenSCAP 内容文件

OpenSCAP 使用 SCAP 内容文件来定义测试规则。 这些内容文件是基于 XCCDF 或 OVAL 标准创建的。 除了 SCAP 安全指南外,您还可以下载公开可用的内容文件并根据您的要求进行自定义。 您可以安装 SCAP 安全指南包以获取默认内容文件模板。 或者,如果您熟悉 XCCDF 或 OVAL,您可以创建自己的内容文件。

我们建议您使用模板来创建您的 SCAP 内容文件。 如果您创建并使用自己的自定义内容文件,风险自负。 如果您的系统因使用自定义内容文件而损坏,您可能无法获得 SUSE 的支持。

创建内容文件后,您需要将文件传输到客户端。 您可以像移动其他文件一样进行此操作,使用物理存储介质,或通过网络使用 Salt(例如, salt-cpSalt 文件服务器),ftpscp

我们建议您创建一个软件包,以将内容文件分发给您使用 SUSE Multi-Linux Manager 管理的客户端。 软件包可以被签名和验证以确保其完整性。 有关更多信息,请参见 自定义通道

4. 查找 OpenSCAP 配置文件

不同的操作系统提供不同的 OpenSCAP 内容文件和控制文件。一个内容文件可能包含多个控制文件。

在基于 RPM 的操作系统上,可使用以下命令确定可用 SCAP 文件的位置:

rpm -ql <scap-security-guide-package-name-from-table>

在基于 DEB 的操作系统上,可使用以下命令确定可用 SCAP 文件的位置:

dpkg -L <scap-security-guide-package-name-from-table>

确定了一个符合您需求的 SCAP 内容文件后,列出客户端上可用的配置文件:

oscap info /usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
Document type: Source Data Stream
Imported: 2021-03-24T18:14:45

Stream: scap_org.open-scap_datastream_from_xccdf_ssg-sle15-xccdf-1.2.xml
Generated: (null)
Version: 1.2
Checklists:
        Ref-Id: scap_org.open-scap_cref_ssg-sle15-xccdf-1.2.xml
                Status: draft
                Generated: 2021-03-24
                Resolved: true
                Profiles:
                        Title: CIS SUSE Linux Enterprise 15 Benchmark
                                Id: xccdf_org.ssgproject.content_profile_cis
                        Title: Standard System Security Profile for SUSE Linux Enterprise 15
                                Id: xccdf_org.ssgproject.content_profile_standard
                        Title: DISA STIG for SUSE Linux Enterprise 15
                                Id: xccdf_org.ssgproject.content_profile_stig
                Referenced check files:
                        ssg-sle15-oval.xml
                                system: http://oval.mitre.org/XMLSchema/oval-definitions-5
                        ssg-sle15-ocil.xml
                                system: http://scap.nist.gov/schema/ocil/2
                        https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15.xml
                                system: http://oval.mitre.org/XMLSchema/oval-definitions-5
Checks:
        Ref-Id: scap_org.open-scap_cref_ssg-sle15-oval.xml
        Ref-Id: scap_org.open-scap_cref_ssg-sle15-ocil.xml
        Ref-Id: scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml
Dictionaries:
        Ref-Id: scap_org.open-scap_cref_ssg-sle15-cpe-dictionary.xml

记下用于执行扫描的文件路径和配置文件。

5. 执行审计扫描

安装或传输内容文件后,您可以执行审计扫描。 可以使用 SUSE Multi-Linux Manager Web UI 触发审计扫描。 您还可以使用 SUSE Multi-Linux Manager API 来安排定期扫描。

过程:升级从 Web UI 运行审计扫描。
  1. 在 SUSE Multi-Linux Manager Web UI 中,导航到 系统  系统列表,选择您要扫描的客户端。

  2. 导航到 Audit 选项卡和 Schedule 子选项卡。

  3. Path to XCCDF Document 字段中,输入要在客户端上使用的 SCAP 模板和控制文件的参数。 例如:

    • Command: /usr/bin/oscap xccdf eval

    • Command-line arguments: --profile xccdf_org.ssgproject.content_profile_stig

    • Path to XCCDF document: /usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml

    如果您经常使用 --fetch-remote-resources 参数,则需要大量的 RAM。 此外,您可能需要增加 file_recv_max_size 的值。

  4. 扫描将在客户端进行下一次安排的同步时运行。

在远程系统上运行之前,XCCDF 内容文件会被验证。 如果内容文件包含无效参数,则测试失败。

过程:升级从 API 运行审计扫描。
  1. 在开始之前,请确保要扫描的客户端上已安装 Python 和 XML-RPC 库。

  2. 选择现有的脚本或创建一个脚本,用于通过 system.scap.scheduleXccdfScan 安排系统扫描。 例如:

    #!/usr/bin/python3
    import xmlrpc.client
    client = xmlrpc.client.ServerProxy('https://server.example.com/rpc/api')
    key = client.auth.login('username', 'password')
    client.system.scap.scheduleXccdfScan(key, <1000010001>,
        '<path_to_xccdf_file.xml>',
        '--profile <profile_name>')
    client.auth.logout(session_key)

    在此示例中:

    • <1000010001> 是系统 ID (sid)。

    • <path_to_xccdf_file.xml> 是客户端上内容文件位置的路径。 例如,/usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml

    • <profile_name>oscap 命令的附加参数。 例如,使用 united_states_government_configuration_baseline (USGCB)。

  3. 在命令提示符下,对您要扫描的客户端运行该脚本。

6. 扫描结果

您运行的扫描信息在 SUSE Multi-Linux Manager Web UI 中。 导航到 审计  OpenSCAP  所有扫描 以查看结果表。 有关此表中数据的更多信息,请参见 All Scans

要确保扫描的详细信息可用,您需要在客户端上启用它。 在 SUSE Multi-Linux Manager Web UI 中,导航到 管理员  组织,然后单击客户端所属的组织。 导航到 Configuration 选项卡,并勾选 Enable Upload of Detailed SCAP Files 选项。 启用后,这将在每次扫描时生成一个额外的 HTML 文件,其中包含额外信息。 结果显示一行类似于以下内容:

Detailed Results: xccdf-report.html xccdf-results.xml scap-yast2sec-oval.xml.result.xml

要从命令行检索扫描信息,请使用 spacewalk-report 命令:

spacewalk-report system-history-scap
spacewalk-report scap-scan
spacewalk-report scap-scan-results

您还可以使用 SUSE Multi-Linux Manager API 通过 system.scap 处理程序查看结果。

7. 删除 SCAP 扫描结果

只有通过配置的保留期的 SCAP 扫描才能被删除。 您可以在 Organization Configuration 部分中配置保留期。

过程:升级配置 SCAP 结果的保留期
  1. 导航到 首页  我的组织  配置

  2. SCAP 下,选中 Allow Deletion of SCAP Results

  3. Allow Deletion After 中输入天数(默认值为 90)。

过程:升级删除 SCAP 扫描结果
  1. 导航到 审计  OpenSCAP  所有扫描

  2. 选择您要删除的扫描的复选框。

  3. 单击 确认

8. 修复

修复 Bash 脚本和 Ansible 剧本包含在相同的 SCAP 安全指南软件包中,以强化客户端系统。例如: 例如:

Listing 1. bash 脚本
/usr/share/scap-security-guide/bash/sle15-script-cis.sh
/usr/share/scap-security-guide/bash/sle15-script-standard.sh
/usr/share/scap-security-guide/bash/sle15-script-stig.sh
Listing 2. Ansible 剧本
/usr/share/scap-security-guide/ansible/sle15-playbook-cis.yml
/usr/share/scap-security-guide/ansible/sle15-playbook-standard.yml
/usr/share/scap-security-guide/ansible/sle15-playbook-stig.yml

在客户端系统中启用 Ansible 后,可以使用远程命令或 Ansible 运行这些脚本和剧本。

8.1. 使用 Bash 脚本运行修复

在所有目标系统上安装 scap-security-guide 软件包。 有关更多信息,请参见 设置 Ansible 控制节点

每个操作系统和发行版的软件包、通道和脚本都是不同的。 示例列在 修复 Bash 脚本示例 部分。

8.1.1. 在单个系统上将 Bash 脚本作为远程命令运行

在单个系统上将 Bash 脚本作为远程命令运行。

  1. 系统  概述 选项卡中,选择您的实例。 然后在 详细信息  远程命令 中,编写一个 Bash 脚本,例如:

    #!/bin/bash
    chmod +x -R /usr/share/scap-security-guide/bash
    /usr/share/scap-security-guide/bash/sle15-script-stig.sh
  2. 单击 日程安排

文件夹和脚本名称在不同的发行版和版本之间会有所变化。 示例列在 修复 Bash 脚本示例 部分。

8.1.2. 在多个系统上使用系统集管理器运行 Bash 脚本

一次性在多个系统上将 Bash 脚本作为远程命令运行。

  1. 创建系统组后,单击 System Groups,然后从表中选择 Use in SSM

  2. System Set Manager 中,在 其他  远程命令 下,编写一个 Bash 脚本,例如:

    #!/bin/bash
    chmod +x -R /usr/share/scap-security-guide/bash
    /usr/share/scap-security-guide/bash/sle15-script-stig.sh
  3. 单击 日程安排

8.2. 修复 Bash 脚本示例

8.2.1. SUSE Linux Enterprise openSUSE 及其变体

示例 SUSE Linux Enterprise 和 openSUSE 脚本数据。

软件包

scap-security-guide

通道
  • SLE12:SLES12 更新

  • SLE15:SLES15 模块 Basesystem 更新

Bash 脚本目录

/usr/share/scap-security-guide/bash/

Bash 脚本
opensuse-script-standard.sh
sle12-script-standard.sh
sle12-script-stig.sh
sle15-script-cis.sh
sle15-script-standard.sh
sle15-script-stig.sh

8.2.2. Red Hat Enterprise Linux 和 CentOS Bash 脚本数据

示例 Red Hat Enterprise Linux 和 CentOS 脚本数据。

centos7-updates 中的 scap-security-guide 仅包含 Red Hat Enterprise Linux 脚本。

软件包

scap-security-guide-redhat

通道
  • SUSE Manager 工具

Bash 脚本目录

/usr/share/scap-security-guide/bash/

Bash 脚本
centos7-script-pci-dss.sh
centos7-script-standard.sh
centos8-script-pci-dss.sh
centos8-script-standard.sh
fedora-script-ospp.sh
fedora-script-pci-dss.sh
fedora-script-standard.sh
ol7-script-anssi_nt28_enhanced.sh
ol7-script-anssi_nt28_high.sh
ol7-script-anssi_nt28_intermediary.sh
ol7-script-anssi_nt28_minimal.sh
ol7-script-cjis.sh
ol7-script-cui.sh
ol7-script-e8.sh
ol7-script-hipaa.sh
ol7-script-ospp.sh
ol7-script-pci-dss.sh
ol7-script-sap.sh
ol7-script-standard.sh
ol7-script-stig.sh
ol8-script-anssi_bp28_enhanced.sh
ol8-script-anssi_bp28_high.sh
ol8-script-anssi_bp28_intermediary.sh
ol8-script-anssi_bp28_minimal.sh
ol8-script-cjis.sh
ol8-script-cui.sh
ol8-script-e8.sh
ol8-script-hipaa.sh
ol8-script-ospp.sh
ol8-script-pci-dss.sh
ol8-script-standard.sh
rhel7-script-anssi_nt28_enhanced.sh
rhel7-script-anssi_nt28_high.sh
rhel7-script-anssi_nt28_intermediary.sh
rhel7-script-anssi_nt28_minimal.sh
rhel7-script-C2S.sh
rhel7-script-cis.sh
rhel7-script-cjis.sh
rhel7-script-cui.sh
rhel7-script-e8.sh
rhel7-script-hipaa.sh
rhel7-script-ncp.sh
rhel7-script-ospp.sh
rhel7-script-pci-dss.sh
rhel7-script-rhelh-stig.sh
rhel7-script-rhelh-vpp.sh
rhel7-script-rht-ccp.sh
rhel7-script-standard.sh
rhel7-script-stig_gui.sh
rhel7-script-stig.sh
rhel8-script-anssi_bp28_enhanced.sh
rhel8-script-anssi_bp28_high.sh
rhel8-script-anssi_bp28_intermediary.sh
rhel8-script-anssi_bp28_minimal.sh
rhel8-script-cis.sh
rhel8-script-cjis.sh
rhel8-script-cui.sh
rhel8-script-e8.sh
rhel8-script-hipaa.sh
rhel8-script-ism_o.sh
rhel8-script-ospp.sh
rhel8-script-pci-dss.sh
rhel8-script-rhelh-stig.sh
rhel8-script-rhelh-vpp.sh
rhel8-script-rht-ccp.sh
rhel8-script-standard.sh
rhel8-script-stig_gui.sh
rhel8-script-stig.sh
rhel9-script-pci-dss.sh
rhosp10-script-cui.sh
rhosp10-script-stig.sh
rhosp13-script-stig.sh
rhv4-script-pci-dss.sh
rhv4-script-rhvh-stig.sh
rhv4-script-rhvh-vpp.sh
sl7-script-pci-dss.sh
sl7-script-standard.sh

8.2.3. Ubuntu Bash 脚本数据

示例 Ubuntu 脚本数据。

软件包

scap-security-guide-ubuntu

通道
  • SUSE Manager 工具

Bash 脚本目录

/usr/share/scap-security-guide/

Bash 脚本
ubuntu1804-script-anssi_np_nt28_average.sh
ubuntu1804-script-anssi_np_nt28_high.sh
ubuntu1804-script-anssi_np_nt28_minimal.sh
ubuntu1804-script-anssi_np_nt28_restrictive.sh
ubuntu1804-script-cis.sh
ubuntu1804-script-standard.sh
ubuntu2004-script-standard.sh

8.2.4. Debian Bash 脚本数据

示例 Debian 脚本数据。

软件包

scap-security-guide-debian

通道
  • SUSE Manager 工具

Bash 脚本目录

/usr/share/scap-security-guide/bash/

Bash 脚本
# Debian 12
debian12-script-anssi_np_nt28_average.sh
debian12-script-anssi_np_nt28_high.sh
debian12-script-anssi_np_nt28_minimal.sh
debian12-script-anssi_np_nt28_restrictive.sh
debian12-script-standard.sh