
Templates and Alerts
Buffer Overflow Template
| Table  | 
 | Argument with  | ||||
| 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | Response | Alert | Alert | 
 | 
 | |
| 
 | Program | Alert Value/Format | Description | |||
| 
 | Field | Field Type | ||||
| 
 | Argument | 
 | 
 | |||
| 
 | 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | 
 | 
 | |
| 
 | argv[9] | Local Time | Integer | <secs> | Local time in | |
| 
 | 
 | 
 | 
 | 
 | 
 | number of seconds | 
| 
 | 
 | 
 | 
 | 
 | 
 | since epoch when | 
| 
 | 
 | 
 | 
 | 
 | 
 | a privileged setuid | 
| 
 | 
 | 
 | 
 | 
 | 
 | program was run | 
| 
 | 
 | 
 | 
 | 
 | 
 | with an argument | 
| 
 | 
 | 
 | 
 | 
 | 
 | that contains a | 
| 
 | 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | 
 | 
 | character. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | 
 | 
 | Refer to Table  | |||
| NOTE | 
 | |||||
| 
 | 
 | 
 | be used to access specific alert information (i.e., pid, ppid) without having to parse the | |||
| 
 | 
 | 
 | string alert fields above. | 
 | ||
| 
 | 
 | 
 | • The template does not detect that an actual buffer overflow attack was successful, | |||
| Limitations | 
 | |||||
| 
 | 
 | 
 | and only detects that one might have been attempted. | 
 | ||
• The template only reports 
| 140 | Appendix A | 
