Templates and Alerts

Modification of Files/Directories Template

File Being Modified

This template generates and forwards the following alert to a response program when a file is modified:

Table A-10

File Being Modified Alert Properties

 

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Field

Alert Value/Format

Description

 

Field

 

Argument

Type

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[1]

Template

Integer

2

Unique code

 

 

code

 

 

assigned to

 

 

 

 

 

template

 

 

 

 

 

 

 

argv[2]

Version

Integer

2

Version of the

 

 

 

 

 

template

 

 

 

 

 

 

 

argv[3]

Severity

Integer

2 if file is truncated, potentially truncated,

Severity

 

 

 

 

deleted, or renamed.

 

 

 

 

 

3 if file’s mode or ownership is modified, or

 

 

 

 

 

file is created, or file is opened for writing or

 

 

 

 

 

appending.

 

 

 

 

 

 

 

 

argv[4]

UTC Time

Integer

<secs>

UTC time in

 

 

 

 

 

number of seconds

 

 

 

 

 

since epoch when

 

 

 

 

 

file is modified.

 

 

 

 

 

 

 

argv[5]

Attacker

String

“uid=<uid>, gid=<gid>, pid=<pid>,

The user ID, group

 

 

 

 

ppid=<ppid>”

ID, process ID,

 

 

 

 

 

and parent

 

 

 

 

 

process ID of the

 

 

 

 

 

process that

 

 

 

 

 

modified the file.

 

 

 

 

 

 

 

argv[6]

Target of

String

“file=<full pathname>,

The full pathname

 

 

Attack

 

mode=<mode>,uid=<uid>,gid=<gid>,

of the file that was

 

 

 

 

modified and the

 

 

 

 

 

 

 

 

 

inode=<inode>,device=<device>”

file’s mode, uid,

 

 

 

 

 

gid, inode, and

 

 

 

 

 

device number.

 

 

 

 

 

 

 

argv[7]

Summary

String

“Filesystem modification or potential

Alert summary

 

 

 

 

modification”

 

 

 

 

 

 

 

Appendix A

149

Page 161
Image 161
HP Host Intrusion Detection System (HIDS) manual Table A-10 File Being Modified Alert Properties