Enhancing Software Resilience and Achieving CIS Level 1 Standards
Apart from regular Ubuntu, Sandbox can also run on CIS level 1 hardened Ubuntu.
To harden the operating system first, please use the guide from here: https://www.open-scap.org/security-policies/scap-security-guide/
The upcoming guide will be divided into two different sections:
Steps to make the installer antivirus-compliant
Fixing post-installation issues, related to the hardened OS
Steps to make the installer antivirus-compliant
You can run this step both before and after the installation, whether you need the installer ZIP compliant or only the installed software itself.
In this section, we will unpack the installer and run a script to modify potentially falsely detected files and malware rules.
Download the latest release from the OPSWAT Portal
If you have internet connection: run the following command:
pip3 install plyaraDo the first step described on the following link: installation/offline-installation (unpack the zip)
Using the same command as previously, but now unpack the
sandbox.zipfile as well (It's in the sandbox-installer directory that you just unzipped)Now you have a directory inside, called
sandbox. Grab the Python scriptharden-yara.pywhich you can find below. Copy it next to thesandboxdirectory.Execute the python script using the following command:
python3 harden_yara.py sandbox/transform/yara/rulesExecute the python script using the following command:
python3 harden_yara.py sandbox/webservice/src/storage/resources/yara_rulesExecute the python script using the following command:
python3 harden_yara.py sandbox/transform/parser/mwconfig-extractorsNow re-zip the
sandboxdirectory and you're done. Example Linux command:7z a -r sandbox.zip sandboxNow you can proceed on installing Sandbox either in an online or offline manner
Below, you can find two different scripts. If you can install plyara pip package, please use the first script, else please use the second!
The version using plyara is more sophisticated, hence it's preferred, however both should work perfectly fine.
After-installation troubleshooting
In some rare cases, you can bump into the following issues after installing Sandbox on a hardened operating system:
Caused by: java.io.IOException: Error initiating config file: can not write to /app/broker.cfg
Caused by: java.io.IOException: Error initiating config file: can not write to /app/transform.cfg
nginx: [emerg] cannot load certificate "/etc/ssl/certs/nginx-selfsigned.crt": BIOnewfile() failed (SSL: error:80000002:systemlibrary::No such file or directory:calling fopen(/etc/ssl/certs/nginx-selfsigned.crt, r) error:10000080:BIO routines::no such file)
If you encounter any of those, you should apply the fix below.
You must have Sandbox installed to run the code below.
In case you installed Sandbox in OFFLINE mode, you will need an extra --offline flag when you execute the script.
Copy the
hardened-install-fix.shscript below on your sandbox installation path. By default, it is/home/sandbox/sandboxStop Sandbox services using
sudo service sandbox stopMake the script executable by executing
sudo chmod +x hardened-install-fix.shExecute the script by using either
sudo ./hardened-install-fix.shorsudo ./hardened-install-fix.sh --offlinedepending, whether the initial install you made was using the offline flag or not.Start Sandbox services by executing
sudo service sandbox start
See the "Technical Datasheet" for a complete list of features: https://docs.opswat.com/filescan/datasheet/technical-datasheet