Templates and Alerts

Alert Summary

Alert Summary

For each alert, Table A-1 lists the attack detected, alert severity and the detection template that generates the alert.

Table A-1

Detection Templates

 

 

 

 

 

 

 

 

Attack Detected

Alert

Alert Severity

Detection Template

 

 

 

 

 

 

A process attempted to execute on its

Buffer overflow

1

Buffer Overflow

 

stack, perhaps as part of a stack

detected

 

Template

 

buffer overflow attack

 

 

 

 

 

 

 

 

 

Potential buffer overflow of a

Potential buffer

1

Buffer Overflow

 

privileged program using an

overflow detected

 

Template

 

unusually long program argument

 

 

 

 

and/or using an argument that

 

 

 

 

contains a non-printable character

 

 

 

 

 

 

 

 

 

A file reference for a privileged

File reference change

1

Race Condition

 

program was changed

 

 

Template

 

 

 

 

 

 

A privileged setuid script was

Race condition attack

1

Race Condition

 

executed via a symbolic link

 

 

Template

 

 

 

 

 

 

A privileged setuid script was

Potential Race

2

Race Condition

 

executed, but not necessarily via a

Condition attack

 

Template

 

symbolic link

 

 

 

 

 

 

 

 

 

 

A read-only file was truncated,

Filesystem

2

Modification of

 

deleted, or renamed

modification or

 

Files/Directories

 

 

 

potential

 

Template

 

 

 

modification

 

 

 

 

 

 

 

 

A read-only file’s mode or ownership

Filesystem

3

Modification of

 

was modified, the file was created, or

modification or

 

Files/Directories

 

the file was opened for writing or

potential

 

Template

 

appending

 

modification

 

 

 

 

 

 

 

 

An append-only file was truncated,

Append-only file

2

Changes to Log File

 

potentially truncated, deleted,

modified or

 

Template

 

renamed, or opened with write

potentially modified

 

 

 

permission in non-append mode

 

 

 

 

 

 

 

 

 

A privileged setuid file was or was

Setuid file created

1

Creation of Setuid

 

potentially created, or the setuid bit

 

 

File Template

 

was turned on a regular file owned

 

 

 

 

by a privileged user, or the owner of

 

 

 

 

a setuid file was changed from a

 

 

 

 

non-privileged user to a privileged

 

 

 

 

user

 

 

 

 

 

 

 

 

 

 

Appendix A

123

Page 135
Image 135
HP Host Intrusion Detection System (HIDS) manual Alert Summary, Table A-1 Detection Templates