| name | cis-ubuntu1804-v220-3-2-1 |
| description | Ensure dccp kernel module is not available |
| category | cis-networking |
| version | 2.2.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-18.04","networking","kernel-module"] |
| cis_id | 3.2.1 |
| cis_benchmark | CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 - Control 3.2.1
Description
The Datagram Congestion Control Protocol (DCCP) is a transport layer protocol that supports streaming media and telephony. DCCP provides a way to gain access to congestion control, without having to do it at the application layer, but does not provide in-sequence delivery.
Rationale
If the protocol is not required, it is recommended that the drivers not be installed to reduce the potential attack surface.
Impact
None.
Audit Procedure
Command Line
Run the following script to verify the dccp module is not available:
#!/usr/bin/bash
{
l_mname="dccp"
l_mtype="net"
l_output="" l_output2="" l_output3=""
l_dl=""
l_loadable="$(modprobe -n -v "$l_mname")"
[ "$(wc -l <<< "$l_loadable")" -gt "1" ] && l_loadable="$(grep -P -- "(^\h*install|\b$l_mname)\b" <<< "$l_loadable")"
if grep -Pq -- '^\h*install \/bin\/(true|false)' <<< "$l_loadable"; then
l_output="$l_output\n - module: \"$l_mname\" is not loadable: \"$l_loadable\""
else
l_output2="$l_output2\n - module: \"$l_mname\" is loadable: \"$l_loadable\""
fi
! lsmod | grep > /dev/null 2>&1;
l_output=
l_output2=
modprobe --showconfig | grep -Pq -- ;
l_output=
l_output2=
[ -z ];
-e
-e
[ -n ] && -e
}