F-7.6: Absence of Audit Logging for NFS Operations¶
Classification¶
- Severity: Medium (Operational/Detection Gap)
- CVSS Vector: N/A (detection evasion, not a direct vulnerability)
- Affected Versions: All NFS versions on Linux
- Root Cause: NFS kernel server bypasses auditd
- Prerequisite: Any of the above attacks in progress
Summary¶
The Linux NFS kernel server (knfsd) processes file operations entirely in kernel space, bypassing the auditd framework. This means that no file access logs are generated for NFS operations, regardless of audit rules configured on the server. An attacker exploiting any NFS vulnerability operates in a completely blind spot — there are no standard detection mechanisms for unauthorized NFS file access.
Technical detail¶
Why auditd doesn't work¶
Linux's audit subsystem hooks into system calls at the VFS layer. Normal file access (local processes, SSH users, etc.) triggers syscalls that auditd can intercept:
NFS kernel server operates differently:
The knfsd kernel threads directly call VFS functions without going through the syscall interface, so auditd rules like -w /etc/shadow -p r do not fire for NFS access.
What IS Logged¶
| Event | Log Source | Reliability |
|---|---|---|
| Mount/unmount | mountd → rmtab, syslog | Unreliable (NfSpy hide bypasses) |
| Service start/stop | systemd journal | Reliable but useless for attacks |
| Export changes | exportfs → syslog | Reliable |
| RPC errors | kernel ring buffer (dmesg) | Sporadic, not comprehensive |
What IS NOT Logged¶
| Event | Detection Possible? |
|---|---|
| File reads via NFS | No |
| File writes via NFS | No |
| UID/GID used per request | No |
| File handle guessing attempts | No (failed GETATTR not logged) |
| Export escape | No |
| Symlink creation/manipulation | No |
| SUID binary upload | No |
Kernel tracepoints (theoretical)¶
The NFS server has some kernel tracepoints that could theoretically be used:
/sys/kernel/debug/tracing/events/nfsd/
├── nfsd_read_start
├── nfsd_write_start
├── nfsd_lookup
├── nfsd_create
├── nfsd_unlink
└── ...
However: - No production tooling exists to consume these for security monitoring - High performance overhead when enabled - Requires custom integration with SIEM - Not enabled by default on any distribution
Impact on defense¶
- No forensic evidence: After an NFS-based data breach, there are no logs to determine what was accessed
- No real-time detection: IDS/SIEM cannot alert on unauthorized NFS access
- Compliance gap: Regulations requiring file access auditing (PCI DSS, HIPAA, SOX) cannot be satisfied for NFS-served data
- Incident response blind spot: Cannot determine scope of compromise through NFS
- Attacker advantage: All other NFS attacks described in this series are undetectable by default
Partial mitigations¶
1. Network-level monitoring¶
Capture and analyze NFS traffic for anomalies:
# Log all NFS connections (coarse)
conntrack -E -p tcp --dport 2049
# Deep packet inspection with tshark
tshark -i eth0 -Y "nfs" -T fields \
-e ip.src -e rpc.auth.uid -e nfs.name \
-e nfs.opcode > /var/log/nfs_access.log
2. eBPF/bpftrace tracing¶
# Trace NFS server file reads (Linux 5.x+)
bpftrace -e 'tracepoint:nfsd:nfsd_read_start {
printf("%s uid=%d file=%s\n", comm, args->fh_uid, args->fh_name);
}'
3. inotifywait (limited)¶
Works for local filesystem events triggered by NFS operations:
# Monitor export directories for changes
inotifywait -m -r /srv/nfs/ -e modify,create,delete,moved_to
Note: Only captures modification events, not reads. High overhead on busy shares.
4. File integrity monitoring¶
Detects modifications after the fact, but not unauthorized reads.
Remediation¶
-
Accept the limitation: Design security around prevention (Kerberos, tight ACLs) rather than detection
-
Use NFSv4 audit features (where available): Some NFSv4 implementations support audit hooks
-
Deploy network-level NFS monitoring: Parse NFS RPC at the network layer
-
Implement eBPF-based tracing for high-security environments:
-
Consider alternative protocols: Samba/CIFS has full audit logging via VFS objects:
-
Use kernel tracepoints with a custom consumer for critical deployments: