Templates and Alerts
Summary
| Summary |
| This appendix describes the detection templates that are used to make up surveillance |
| groups. This appendix also describes the alerts that are passed to the System Manager |
| and to response programs by the |
Alerts | • “Alert Summary” on page 123 |
Limitations | • “Limitations” on page 128 |
Property Types | • “Template Property Types” on page 129 |
Templates and | • “Buffer Overflow Template” on page 134 |
associated alerts | • “Changes to Log File Template” on page 152 |
| |
| • “Creation of Setuid File Template” on page 155 |
| • “Creation of |
| • “Modification of Another User’s File Template” on page 163 |
| • “Modification of Files/Directories Template” on page 146 |
| • “Login/Logout Template” on page 167 |
| • “Race Condition Template” on page 141 |
| • “Repeated Failed Logins Template” on page 173 |
| • “Repeated Failed su Commands Template” on page 176 |
122 | Appendix A |