Quality Assurance Debugging

How does your quality assurance group know if an issue that "never happened before" or "cannot possibly be this application" is related to CSA or not?

They can take a severe route, if your policy allows it, and remove CSA to see if that changes the situation. However, by now you should know that there are alternative methods to most quality assurance and testing issues. The following are suggestions your quality assurance group can use.

There are two ways to disable CSA temporarily that do not involve an uninstall/reboot:

• The first is to simply choose Off as the security level. You can do this either in the user interface or by right-clicking on the red CSA flag in the Windows taskbar (or Linux taskbar if you are running a Windows-based user interface), as shown in Figure 5-14. Depending on your policy, you might be asked a question or two to verify that you want to set the security level to Off. After this is complete, all CSA policies are in bypass mode except self-protection of the CSA. This means that none of your policies will trigger or affect any action that occurs on the system, unless it affects the CSA files.

Figure 5-14 Cisco Security Agent Taskbar Flag Menu

Figure 5-14 Cisco Security Agent Taskbar Flag Menu

• The second way to disable CSA temporarily is to stop the CSA service. This is accomplished under Windows by opening a command shell (click the Start menu, select Run, and enter: cmd in the box that appears and click OK. A command window should then pop up; see Figure 5-15 for an example. Enter net stop csagent and press Enter. You are prompted (again depending on your policy settings) to confirm that you want to stop CSA. After you confirm this, you should see a confirmation that the service was stopped successfully.

After these processes are complete, all CSA services stop. This includes self-protection of the agent and its files and settings.

Figure 5-15 Cisco Security Agent Service Stop from a Command Window in Microsoft Windows

C:\WINNT\syslem32\cmd.

I- Don't ask me again DeFault action will be taken in 1- minutes:46 seconds

Figure 5-15 Cisco Security Agent Service Stop from a Command Window in Microsoft Windows

C:\WINNT\syslem32\cmd.

I- Don't ask me again DeFault action will be taken in 1- minutes:46 seconds

The following situation rarely occurs but you should understand it. You have an application that crashes, but it did not do this before installing CSA. However, after installing CSA (regardless of whether the agent funs or not), it crashes. This usually happens with Computer Aided Design (CAD) applications or other related applications that have extremely tight licensing code. This type of code watches for anything that looks like an operating system debugger and crashes if it thinks someone is trying to hack its licensing code. If you run into this situation and uninstalling CSA fixes the application, you can add the application in question to the built-in Cisco Security Agent application class <Processes Requiring Kernel Only Protections See Figure 5-16 for an example of an application control rule that allows an application class AutoCAD to run properly.

Figure 5-16 Cisco Security Agent Application Control Rule to Add AutoCAD Application Class to <Processes Requiring Kernel Only Protection>

Figure 5-16 Cisco Security Agent Application Control Rule to Add AutoCAD Application Class to <Processes Requiring Kernel Only Protection>

You can look at the log files for CSA through any of the following:

• Messages selection, as shown in Figure 5-17.

• The security log, as displayed in Figure 5-18.

• The endpoint log files from the log/ subdirectory of the directory you installed CSA in (usually C:\Program Files\Cisco Systems\CSAgent on Windows), as shown in Figure 5-19.

Figure 5-17 Cisco Security Agent Messages Window

Figure 5-17 Cisco Security Agent Messages Window

Figure 5-18 Cisco Security Agent Security Log from the Windows User Interface Screen

Figure 5-19 Cisco Security Agent csalog.txt File Open in Windows Notepad Application

tory of C:\Prograri FilesSCisco Systeitis\CSflgentMog

09/30/2005 09/30/2005 07/29/2005 09/30/2005 07/29/2005 09/29/2005 09/30/2005 09/07/2005 09/30/2005 09/30/2005 09/30/2005 09/30/2005 09/30/2005 09/30/2005

02:49p <1

02:49p <] 11:15p 02:49p ii:15p 04:29p 02:l5p 02: 16p 02:45p 02:44p 02:49p 02:49p 02:45p 02:45p 12 File<s>

19,293 CSAgent-Install.log 18,431 csalog.txt 20,619 driver_install.log 701 request-07-14-16.rtr 464 request—29—17-20.rtr 2,604 request—29—23-17.rtr 284 request-30-14-16.rtr 7,368 securitylog.txt

0 trackdb20050930-0.dir 8,192 tracMb20050930-0.pag 4,096 trackdb20050930.dir 16,384 trackdb20050930.pag 9B,436 bytes

C:\Program FilesSCisco Systens\CSAgent\log>notepad csalog.txt ran FilesSCisco SystensSCSAgentSlog>

csalog - Notepad

File Edit Format Help

'20052005200520052005200520052005200520052005200520052005200520052005200520052005200520052005-

09-3 0 14:4 5: 09-3 0 14:4 5: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-30 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49: 09-3 0 14:49:

01.973' 02.020 13.833 13.833 13.895 14.036 14.255 14.317 14.505 14.505 14.505 14.552 14.817 15.130 15.192 15.286 15.317 15.317 15.348 15.583 15.755 16.786 13.114

PID=4740] PID=4740] PID=400] PI D=400] PI D=400] PID=4740" PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PID=4740 PI D=4740 PI D=4740 PI D=4740 PI D=4740 PI D=4740"

[CsaCtrl]: Stopped process [CsaCtrl]: Service CSAgent [CsaCtrl]: .

[CsaCtrl]: Service CSAgent [CsaCtrl]: Started pi 'Csamanager"' Csamanager csamanager csamanager csamanager csamanager csamanager csamanager csamanager csamanager csamanager csamanager csamanager

Csamanagi

Csamanagi

Csamanagi

Csamanagi

Csamanagi mgr.exe pid=4 740 Csamanager starting ...

Agent is 'managed', version=V4.5-1 build 616, os="Windows 2000', os vt Listening for requests on fixed channel Global\csamanager_ch_00000000 initialized upload randomizer to 47 warning: oldest message is 252500 milliseconds old uskaBoostPriarity: Event handler thread priority is 15 polling interval = 600 sec get_system_params is unable to get dns server list load_rules: compiled runtime rule program (0} Ct=2 50 ms} coMBui1dTrees: started.

load_rules: configured rule engine (0^ (t=546 ms} mc Reachability state has been set to 'Not Reachable'. Agent initialization complete. Start Polling.

COMBui1dTrees: finished, elapsedTime=406 millisec

DoGUIDSetAssignments: COM id trees were created. Number of rcvd reque; Added agent UI channel-index=0 for session=0, user='Administrator', sn MC Reachability state has been set to 'Reachable*.

One of these preceding methods usually assists the quality assurance staff in locating and narrowing down a problem without having to uninstall and reinstall the CSA for every issue that arises.

Most software, however, works with CSA and does not cause issues or require policy changes. The default policies included with CSA are designed and tested to ensure a secure machine while treating a wide variety of actions as "normal" behaviors with no interaction or interruption.

It is important to remember that CSA is installed. Many of its actions are obvious and can be worked through in simple, easy steps or through straightforward testing and policy changes. However, using the modular and configurable features of CSA allows you to easily work through insecurely coded programs or actions.

Your quality assurance group should help you during a CSA pilot and with ongoing application deployment and provide feedback as it walks through its normal testing procedures and processes.

Continue reading here: Agent Kit Dissection

Was this article helpful?

0 0