Templates and Alerts
Creation of
Table |
| ||||||
|
|
|
|
|
|
|
|
| Response |
| Alert | Alert |
|
|
|
| Program |
| Field |
| Alert Value/Format | Description | |
|
| Field |
| ||||
| Argument |
| Type |
|
|
| |
|
|
|
|
|
| ||
|
|
|
|
|
|
| |
| argv[8] | Details | String |
| “User with uid <uid> <performed action | Detailed alert | |
|
|
|
|
|
| on the file> <full | description |
|
|
|
|
|
| pathname>(type=<type>,inode=<inode>, |
|
|
|
|
|
|
| device<device>) when executing |
|
|
|
|
|
|
| <program>(type=<type>,inode=<inode>,d |
|
|
|
|
|
|
| evice=<device>), invoked as follows: |
|
|
|
|
|
|
| <argv[0]> <argv[1]>..., as process with pid |
|
|
|
|
|
|
| <pid> and ppid <ppid> and running with |
|
|
|
|
|
|
| effective uid=<euid> and with effective |
|
|
|
|
|
|
| gid=<egid>. |
|
|
|
|
|
|
| where <performed action on the file> is |
|
|
|
|
|
|
| set to one of the following: |
|
|
|
|
|
|
| "created the world writable file" |
|
|
|
|
|
|
| "created the world writable directory" |
|
|
|
|
|
|
| "created the |
|
|
|
|
|
|
| special file" |
|
|
|
|
|
|
| "created the world writable block special |
|
|
|
|
|
|
| file" |
|
|
|
|
|
|
| "created the world writable pipe (fifo) file" |
|
|
|
|
|
|
| "renamed the |
|
|
|
|
|
|
| "changed the owner of the world writable |
|
|
|
|
|
|
| file" |
|
|
|
|
|
|
| "enabled the world writable permission on |
|
|
|
|
|
|
| file" |
|
|
|
|
|
|
| "performed system call <number> on the |
|
|
|
|
|
|
| file" |
|
|
|
|
|
|
|
| |
| argv[9] | Local Time | Integer |
| <secs> | Local time in | |
|
|
|
|
|
|
| number of |
|
|
|
|
|
|
| seconds since |
|
|
|
|
|
|
| epoch when a |
|
|
|
|
|
|
| world writable |
|
|
|
|
|
|
| file is created |
|
|
|
|
|
|
| |
|
|
| Refer to Table | ||||
NOTE |
| ||||||
|
|
| be used to access specific alert information (i.e., pid, ppid) without having to parse the | ||||
|
|
| string alert fields above. |
|
| ||
|
|
|
|
|
|
|
|
Appendix A | 161 |