1. Manuals
  2. Brands
  3. Computer Equipment
  4. Server
  5. IBM
  6. Computer Equipment
  7. Server

IBM 10 SP1 EAL4 Figure 5-69: Audit framework components

1 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 246
Download on canonical page 246 pages, 2.94 Mb
Figure 5-69: Audit framework components

5.6.1.1 Audit kernel components

Linux Audit of the SLES kernel includes three kernel-side components relating to the audit functionality. The
first component is a generic mechanism for creating audit records and communicating with user space. The
communication is achieved via netlink socket interface. Netlink enables the transfer of information between
kernel modules and user-space processes. It provides kernel-user space bidirectional communication links.
Linux Audit consists of a standard sockets-based interface for user processes and an internal kernel API for
kernel modules.

5.6.1.1.1 Kernel-userspace interface

On top of netlink, there exists the generic netlink family that provides simplified access for less demanding
users. This introduces a control for ID management and name resolution, and possesses a new type of safety
interface for netlink messages and attributes handling. This interface also features simplified message
constructing, validation capabilities, and documentation.
This first component also receives user-space commands to control the operation of the audit framework and
to set the audit filter rules and file system watch points.
132
MENU

Models

Contents