diff --git a/docs/anolis-security-benchmark-summary-of-rules.md b/docs/summary-of-rules.md similarity index 100% rename from docs/anolis-security-benchmark-summary-of-rules.md rename to docs/summary-of-rules.md diff --git a/tools/remediation-kits/README.md b/tools/remediation-kits/README.md index c52230e49615a00742d83e215b61d184d03ca641..bc0207f38fe56b2949cda5fc8412d45675e0e8de 100644 --- a/tools/remediation-kits/README.md +++ b/tools/remediation-kits/README.md @@ -10,6 +10,10 @@ - Anolis_security_benchmark_level1.config -- 配置文件,用于存储待加固的项目编号 +- Reference_DengBaoThree.config -- 此 config 文件包含的编号为:已发布的 benchmark 中参考了 等保2.0三级 标准的规则。其中包含 level 3 的规则,需谨慎使用 + +- Reference_CIS.config -- 此 config 文件包含的编号为:已发布的 benchmark 中参考了 CIS 标准的规则。具体可在 benchmark Markdown 文档的参考一项中查看 + - run_Anolis_remediation_kit.sh -- 可执行文件,用于调用加固脚本对系统进行加固 - config(目录) -- 用于存放config文件 diff --git a/tools/remediation-kits/config/Anolis_security_benchmark_level1.config b/tools/remediation-kits/config/Anolis_security_benchmark_level1.config index ea93e5aa495030617bccf3d506fdaad96e1f6a82..bd42598adba48fcf4aebe34d8253c51afff91eb2 100644 --- a/tools/remediation-kits/config/Anolis_security_benchmark_level1.config +++ b/tools/remediation-kits/config/Anolis_security_benchmark_level1.config @@ -21,11 +21,17 @@ 1.39 1.40 1.41 +1.42 +1.43 +1.44 +1.45 +1.46 2.11 2.14 2.16 2.17 2.18 +2.19 3.5 4.2 4.3 @@ -49,4 +55,5 @@ 4.66 4.67 4.68 -5.1 \ No newline at end of file +5.1 +4.1 \ No newline at end of file diff --git a/tools/remediation-kits/config/Anolis_security_benchmark_level3.config b/tools/remediation-kits/config/Anolis_security_benchmark_level3.config index cc12a56ede7d7a05d2cbfd650b23cc2cfe454db8..120b11e261bdc8d9843e65513e69d6650c448700 100644 --- a/tools/remediation-kits/config/Anolis_security_benchmark_level3.config +++ b/tools/remediation-kits/config/Anolis_security_benchmark_level3.config @@ -21,13 +21,23 @@ 1.39 1.40 1.41 +1.42 +1.43 +1.44 +1.45 +1.46 2.11 2.14 2.16 2.17 2.18 +2.19 2.20 +2.21 +2.22 +2.23 3.5 +3.19 4.2 4.3 4.8 @@ -54,4 +64,5 @@ 5.1 5.2 5.3 -5.4 \ No newline at end of file +5.4 +4.1 \ No newline at end of file diff --git a/tools/remediation-kits/config/Reference_CIS.config b/tools/remediation-kits/config/Reference_CIS.config new file mode 100644 index 0000000000000000000000000000000000000000..183e7320024f1a03a6427e39a22dde1a172b0b76 --- /dev/null +++ b/tools/remediation-kits/config/Reference_CIS.config @@ -0,0 +1,50 @@ +1.2 +1.3 +1.4 +1.5 +1.6 +1.7 +1.8 +1.14 +1.17 +1.20 +1.21 +1.22 +1.24 +1.27 +1.28 +1.29 +1.31 +1.32 +1.34 +1.36 +1.37 +1.39 +1.40 +2.11 +2.14 +2.16 +2.17 +2.18 +3.5 +4.2 +4.3 +4.8 +4.9 +4.11 +4.13 +4.44 +4.45 +4.46 +4.48 +4.49 +4.50 +4.51 +4.52 +4.55 +4.57 +4.59 +4.62 +4.63 +4.64 +4.1 \ No newline at end of file diff --git a/tools/remediation-kits/config/Reference_DengBaoThree.config b/tools/remediation-kits/config/Reference_DengBaoThree.config new file mode 100644 index 0000000000000000000000000000000000000000..1da9a40c428cd2965b840cae6964a5c2d823fccc --- /dev/null +++ b/tools/remediation-kits/config/Reference_DengBaoThree.config @@ -0,0 +1,16 @@ +1.17 +1.27 +1.36 +1.39 +1.40 +1.42 +1.43 +1.44 +1.45 +1.46 +2.20 +2.21 +2.22 +2.23 +3.5 +3.19 \ No newline at end of file diff --git a/tools/scanners/README.md b/tools/scanners/README.md index 5adccfa856f87dd2fbf6226c3dc8d74d4fbf89fd..2eb36e38fb5eb18b5ca5d99a06c0396b3e6c253e 100644 --- a/tools/scanners/README.md +++ b/tools/scanners/README.md @@ -10,6 +10,10 @@ - Anolis_security_benchmark_level1.config -- 配置文件,用于存储待扫描的项目编号 +- Reference_DengBaoThree.config -- 此 config 文件包含的编号为:已发布的 benchmark 中参考了 等保2.0三级 标准的规则 + +- Reference_CIS.config -- 此 config 文件包含的编号为:已发布的 benchmark 中参考了 CIS 标准的规则。具体可在 benchmark Markdown 文档的参考一项中查看 + - run_Anolis_scanners.sh -- 可执行文件,用于调用扫描脚本对系统进行安全合规扫描 - config(目录) -- 用于存放config文件 diff --git a/tools/scanners/config/Anolis_security_benchmark_level1.config b/tools/scanners/config/Anolis_security_benchmark_level1.config index 447a37b35fa05ba1487c0432d30589e87d2a4fe8..ee4d7fd25bea41069d295a34be34157008b0d968 100644 --- a/tools/scanners/config/Anolis_security_benchmark_level1.config +++ b/tools/scanners/config/Anolis_security_benchmark_level1.config @@ -37,6 +37,13 @@ 1.39 1.40 1.41 +1.42 +1.43 +1.44 +1.45 +1.46 +1.47 +1.49 2.1 2.2 2.3 @@ -72,6 +79,12 @@ 3.15 3.16 3.17 +3.18 +3.20 +3.21 +3.22 +3.23 +3.24 4.1 4.2 4.3 diff --git a/tools/scanners/config/Anolis_security_benchmark_level2.config b/tools/scanners/config/Anolis_security_benchmark_level2.config index 8d91922e4e9c80d8f9811f8eb972441a3162bfca..e42c3eb972cc076f968de5e1560d7d52dd9b095a 100644 --- a/tools/scanners/config/Anolis_security_benchmark_level2.config +++ b/tools/scanners/config/Anolis_security_benchmark_level2.config @@ -39,6 +39,14 @@ 1.39 1.40 1.41 +1.41 +1.42 +1.43 +1.44 +1.45 +1.46 +1.47 +1.49 2.1 2.2 2.3 @@ -75,6 +83,12 @@ 3.15 3.16 3.17 +3.18 +3.20 +3.21 +3.22 +3.23 +3.24 4.1 4.2 4.3 diff --git a/tools/scanners/config/Anolis_security_benchmark_level3.config b/tools/scanners/config/Anolis_security_benchmark_level3.config index e81ac2b4c3a32305a2747034dbfb4ec480b0840d..53d8fefe9cbe03a02868f5263c00c5476c6382aa 100644 --- a/tools/scanners/config/Anolis_security_benchmark_level3.config +++ b/tools/scanners/config/Anolis_security_benchmark_level3.config @@ -39,6 +39,13 @@ 1.39 1.40 1.41 +1.42 +1.43 +1.44 +1.45 +1.46 +1.47 +1.49 2.1 2.2 2.3 @@ -59,6 +66,9 @@ 2.18 2.19 2.20 +2.21 +2.22 +2.23 3.1 3.2 3.3 @@ -76,6 +86,13 @@ 3.15 3.16 3.17 +3.18 +3.19 +3.20 +3.21 +3.22 +3.23 +3.24 4.1 4.2 4.3 diff --git a/tools/scanners/config/Anolis_security_benchmark_level4.config b/tools/scanners/config/Anolis_security_benchmark_level4.config index 0632f9740c09643a980e1b42eb998816f818df97..16ed199394c65403be8efe8ef857b45cac69a65c 100644 --- a/tools/scanners/config/Anolis_security_benchmark_level4.config +++ b/tools/scanners/config/Anolis_security_benchmark_level4.config @@ -39,6 +39,13 @@ 1.39 1.40 1.41 +1.42 +1.43 +1.44 +1.45 +1.46 +1.47 +1.49 2.1 2.2 2.3 @@ -59,6 +66,9 @@ 2.18 2.19 2.20 +2.21 +2.22 +2.23 3.1 3.2 3.3 @@ -76,6 +86,13 @@ 3.15 3.16 3.17 +3.18 +3.19 +3.20 +3.21 +3.22 +3.23 +3.24 4.1 4.2 4.3 diff --git a/tools/scanners/config/Reference_CIS.config b/tools/scanners/config/Reference_CIS.config new file mode 100644 index 0000000000000000000000000000000000000000..272991e948664f89b41e4a25d7851146072b3d1c --- /dev/null +++ b/tools/scanners/config/Reference_CIS.config @@ -0,0 +1,139 @@ +1.1 +1.2 +1.3 +1.4 +1.5 +1.6 +1.7 +1.8 +1.9 +1.10 +1.11 +1.12 +1.13 +1.14 +1.15 +1.16 +1.17 +1.18 +1.19 +1.20 +1.21 +1.22 +1.23 +1.24 +1.25 +1.26 +1.27 +1.28 +1.29 +1.30 +1.31 +1.32 +1.33 +1.34 +1.35 +1.36 +1.37 +1.38 +1.39 +1.40 +2.1 +2.2 +2.3 +2.4 +2.5 +2.6 +2.7 +2.8 +2.9 +2.10 +2.11 +2.12 +2.13 +2.14 +2.15 +2.16 +2.17 +2.18 +2.19 +3.1 +3.2 +3.3 +3.4 +3.5 +3.6 +3.7 +3.8 +3.9 +3.10 +3.11 +3.12 +3.13 +3.14 +3.15 +4.1 +4.2 +4.3 +4.4 +4.5 +4.6 +4.7 +4.8 +4.9 +4.10 +4.11 +4.12 +4.13 +4.14 +4.15 +4.16 +4.17 +4.18 +4.19 +4.20 +4.21 +4.22 +4.23 +4.24 +4.25 +4.26 +4.27 +4.28 +4.29 +4.30 +4.31 +4.32 +4.33 +4.34 +4.35 +4.36 +4.37 +4.38 +4.39 +4.40 +4.41 +4.42 +4.43 +4.44 +4.45 +4.46 +4.47 +4.48 +4.49 +4.50 +4.51 +4.52 +4.53 +4.54 +4.55 +4.56 +4.57 +4.58 +4.59 +4.60 +4.61 +4.62 +4.63 +4.64 +4.65 \ No newline at end of file diff --git a/tools/scanners/config/Reference_DengBaoThree.config b/tools/scanners/config/Reference_DengBaoThree.config new file mode 100644 index 0000000000000000000000000000000000000000..53a80e6ff388ba83ab1eecf2a17a9061e04d6a4d --- /dev/null +++ b/tools/scanners/config/Reference_DengBaoThree.config @@ -0,0 +1,30 @@ +1.17 +1.27 +1.27 +1.36 +1.39 +1.40 +1.42 +1.43 +1.44 +1.45 +1.46 +1.47 +1.49 +2.20 +2.21 +2.22 +2.23 +3.14 +3.15 +3.17 +3.18 +3.19 +3.20 +3.21 +3.22 +3.23 +3.24 +3.4 +3.5 +4.31 \ No newline at end of file