Templates and Alerts

Changes to Log File Template

These properties can be used to filter out alerts generated when a particular program modifies a particular file other than appending . See “Type II: Pathnames/Programs Pairs” on page 130 for a detailed description of these property pairs.

Alerts generated “Append-Only File Being Modified” on page 153 by this template

Append-Only File Being Modified

This template generates and forwards the following alerts to a response program when a file is modified in a way other than being appended to:

Table A-12

Append-Only File Being Modified Alert Properties

 

 

 

 

 

 

 

 

Response

Alert

Alert Field

 

 

 

Program

Alert Value/Format

Description

 

Field

Type

 

Argument

 

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[1]

Template

Integer

3

Unique code

 

 

code

 

 

assigned to

 

 

 

 

 

template

 

 

 

 

 

 

 

argv[2]

Version

Integer

2

Version of the

 

 

 

 

 

template

 

 

 

 

 

 

 

argv[3]

Severity

Integer

2

Severity

 

 

 

 

 

 

 

argv[4]

UTC Time

Integer

<secs>

UTC time in

 

 

 

 

 

number of seconds

 

 

 

 

 

since epoch when

 

 

 

 

 

file is modified.

 

 

 

 

 

 

 

argv[5]

Attacker

String

“uid=<uid>, gid=<gid>, pid=<pid>,

The user ID, group

 

 

 

 

ppid=<ppid>”

ID, process ID,

 

 

 

 

 

and parent

 

 

 

 

 

process ID of the

 

 

 

 

 

process that

 

 

 

 

 

modified the file

 

 

 

 

 

 

 

argv[6]

Target of

String

“file=<full pathname>,

The full pathname

 

 

Attack

 

mode=<mode>,uid=<uid>,gid=<gid>,

of the file that was

 

 

 

 

modified and the

 

 

 

 

 

 

 

 

 

inode=<inode>,device=<device>”

file’s mode, uid,

 

 

 

 

 

gid, inode, and

 

 

 

 

 

device number.

 

 

 

 

 

 

 

argv[7]

Summary

String

“Append-only file modified or

Alert summary

 

 

 

 

potentially modified”

 

 

 

 

 

 

 

Appendix A

153

Page 165
Image 165
HP Host Intrusion Detection System (HIDS) manual Append-Only File Being Modified