HP UX Auditing System Extensions manual

Page 25

AudFilter Product pre-filteringFine-grained filtering in the kernel to selectively record the audit records that were generated and stored in the audit trail. This reduces the size of the audit trail and enhances system call pre- and post-filtering by supporting rules-based filtering as a function of other attributes, such as system call parameters (for example, the open(2) oflag parameter), file owner, file system on which a file resides, and system call errno.

AudReport Product post-filteringFine-grained filtering in user space to selectively extract audit records that were generated and stored in the audit trail, and to produce useful reports.

Primary Audit Trail

The current audit trail in which audit records are being written.

Profile

A set of base events defined for a particular type of system (for example, web server and file server).

Secondary Audit Trail

The audit trail in which audit records will be written when certain capacity limits are reached for the Primary Audit Trail.

Self-Auditing Events

An auditable event that describes a series of actions performed by a program in order to provide a more high-level and meaningful description of an event (for example, user login event), instead of a low system call level description provided by a series of System Call Events.

Self-Auditing Program

A privileged program that produces self-auditing events. These are not necessarily Audit Aware Programs.

System Call Events

An auditable event that describes the invocation of a security relevant system call.

25

Image 25
Contents HP-UX 11i v2 and 11i v3 Security Configuring and Managing the Auditing SystemIntroduction AudienceAuditing system overview CommandsArchitecture Daemons System callsFiles Audit trail Audit tagsAudit events System call table records Version recordsPID identification records System call audit recordsSelf-auditing programs Audit tunable parameters HP-UX 11i v3 onlyAudit aware Page Newgrp1 modaccess Setfilexsec1M modaccess Could not lock file Networking service = ftp Executing login pid = pid. ipcopenAudit unaware Remote user Usernameunspecified Local SystemDynamically Linked Kernel Modules Auditing system extensions HP-UX 11i v3 onlyAudit Filtering Installation HP-UX Auditing System AdministrationAudit Reporting Configuring users for audit ConfigurationUserdbset command. See userdbset1M and userdb4 Configuring audit filtering Configuring events for auditConfiguring audit settings to be preserved across reboots Role, operation, object Configuring rolesManagement Reads the /etc/rc.config.d/auditing fileEnabling auditing Disabling auditingService Provider Interfaces SPIs Writing a Dpms service moduleDpms service module implementation Best practicesAudit generation and capture Audit policyAudit log analysis Audit retention and storageAudit log configuration, security, and protection TroubleshootingOpt/audit/AudReport/bin Page Audwrite2 GlossaryPage Send comments to HP For more information