HP Host Intrusion Detection System (HIDS) manual Limitations, 140

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 152
Image 152

Templates and Alerts

Buffer Overflow Template

Table A-5

 

Argument with Non-printable Character Alert Properties (Continued)

 

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Alert Value/Format

Description

 

Field

Field Type

 

Argument

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[9]

Local Time

Integer

<secs>

Local time in

 

 

 

 

 

 

number of seconds

 

 

 

 

 

 

since epoch when

 

 

 

 

 

 

a privileged setuid

 

 

 

 

 

 

program was run

 

 

 

 

 

 

with an argument

 

 

 

 

 

 

that contains a

 

 

 

 

 

 

non-printable

 

 

 

 

 

 

character.

 

 

 

 

 

 

 

 

 

 

Refer to Table B-1 in Appendix B for the definition of argv[10] through argv[32] that can

NOTE

 

 

 

 

be used to access specific alert information (i.e., pid, ppid) without having to parse the

 

 

 

string alert fields above.

 

 

 

 

• The template does not detect that an actual buffer overflow attack was successful,

Limitations

 

 

 

 

and only detects that one might have been attempted.

 

• The template only reports exec-on-stack buffer overflow attacks on HP-UX 11i when exec-on-stack protection is enabled.

140

Appendix A

Page 152
Image 152
HP Host Intrusion Detection System (HIDS) manual Limitations, 140