Skip to content

F-7.6: Absence of Audit Logging for NFS Operations

Classification

  • Severity: Medium (Operational/Detection Gap)
  • CVSS Vector: N/A (detection evasion, not a direct vulnerability)
  • Affected Versions: All NFS versions on Linux
  • Root Cause: NFS kernel server bypasses auditd
  • Prerequisite: Any of the above attacks in progress

Summary

The Linux NFS kernel server (knfsd) processes file operations entirely in kernel space, bypassing the auditd framework. This means that no file access logs are generated for NFS operations, regardless of audit rules configured on the server. An attacker exploiting any NFS vulnerability operates in a completely blind spot — there are no standard detection mechanisms for unauthorized NFS file access.

Technical detail

Why auditd doesn't work

Linux's audit subsystem hooks into system calls at the VFS layer. Normal file access (local processes, SSH users, etc.) triggers syscalls that auditd can intercept:

Local process → open() syscall → VFS → audit hook → filesystem

NFS kernel server operates differently:

NFS RPC → knfsd (kernel thread) → VFS → filesystem
                                   ↑
                          No syscall boundary = no audit hook

The knfsd kernel threads directly call VFS functions without going through the syscall interface, so auditd rules like -w /etc/shadow -p r do not fire for NFS access.

What IS Logged

Event Log Source Reliability
Mount/unmount mountd → rmtab, syslog Unreliable (NfSpy hide bypasses)
Service start/stop systemd journal Reliable but useless for attacks
Export changes exportfs → syslog Reliable
RPC errors kernel ring buffer (dmesg) Sporadic, not comprehensive

What IS NOT Logged

Event Detection Possible?
File reads via NFS No
File writes via NFS No
UID/GID used per request No
File handle guessing attempts No (failed GETATTR not logged)
Export escape No
Symlink creation/manipulation No
SUID binary upload No

Kernel tracepoints (theoretical)

The NFS server has some kernel tracepoints that could theoretically be used:

/sys/kernel/debug/tracing/events/nfsd/
├── nfsd_read_start
├── nfsd_write_start
├── nfsd_lookup
├── nfsd_create
├── nfsd_unlink
└── ...

However: - No production tooling exists to consume these for security monitoring - High performance overhead when enabled - Requires custom integration with SIEM - Not enabled by default on any distribution

Impact on defense

  • No forensic evidence: After an NFS-based data breach, there are no logs to determine what was accessed
  • No real-time detection: IDS/SIEM cannot alert on unauthorized NFS access
  • Compliance gap: Regulations requiring file access auditing (PCI DSS, HIPAA, SOX) cannot be satisfied for NFS-served data
  • Incident response blind spot: Cannot determine scope of compromise through NFS
  • Attacker advantage: All other NFS attacks described in this series are undetectable by default

Partial mitigations

1. Network-level monitoring

Capture and analyze NFS traffic for anomalies:

# Log all NFS connections (coarse)
conntrack -E -p tcp --dport 2049

# Deep packet inspection with tshark
tshark -i eth0 -Y "nfs" -T fields \
    -e ip.src -e rpc.auth.uid -e nfs.name \
    -e nfs.opcode > /var/log/nfs_access.log

2. eBPF/bpftrace tracing

# Trace NFS server file reads (Linux 5.x+)
bpftrace -e 'tracepoint:nfsd:nfsd_read_start {
    printf("%s uid=%d file=%s\n", comm, args->fh_uid, args->fh_name);
}'

3. inotifywait (limited)

Works for local filesystem events triggered by NFS operations:

# Monitor export directories for changes
inotifywait -m -r /srv/nfs/ -e modify,create,delete,moved_to

Note: Only captures modification events, not reads. High overhead on busy shares.

4. File integrity monitoring

# AIDE baseline for NFS export directories
aide --check --config=/etc/aide/aide.conf

Detects modifications after the fact, but not unauthorized reads.

Remediation

  1. Accept the limitation: Design security around prevention (Kerberos, tight ACLs) rather than detection

  2. Use NFSv4 audit features (where available): Some NFSv4 implementations support audit hooks

  3. Deploy network-level NFS monitoring: Parse NFS RPC at the network layer

  4. Implement eBPF-based tracing for high-security environments:

    # Example: trace all NFS file operations
    bpftrace -e 'kprobe:nfsd_read { printf("read: %s\n", str(arg1)); }'
    

  5. Consider alternative protocols: Samba/CIFS has full audit logging via VFS objects:

    # smb.conf
    vfs objects = full_audit
    full_audit:success = open read write unlink
    

  6. Use kernel tracepoints with a custom consumer for critical deployments:

    echo 1 > /sys/kernel/debug/tracing/events/nfsd/enable
    cat /sys/kernel/debug/tracing/trace_pipe | logger -t nfsd-audit &