
Templates and Alerts
Modification of Another User’s File Template
| Table  | |||||
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | Response | Alert | Alert | 
 | 
 | 
| 
 | Program | Alert Value/Format | Description | ||
| 
 | Field | Field Type | |||
| 
 | Argument | 
 | 
 | ||
| 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[4] | UTC Time | Integer | <secs> | UTC time in | 
| 
 | 
 | 
 | 
 | 
 | number of seconds | 
| 
 | 
 | 
 | 
 | 
 | since epoch when | 
| 
 | 
 | 
 | 
 | 
 | a file is modified | 
| 
 | 
 | 
 | 
 | 
 | by a  | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[5] | Attacker | String | “uid=<uid>, gid=<gid>, pid=<pid>, | The user ID, group | 
| 
 | 
 | 
 | 
 | ppid=<ppid>” | ID, process ID, | 
| 
 | 
 | 
 | 
 | 
 | and parent | 
| 
 | 
 | 
 | 
 | 
 | process ID of the | 
| 
 | 
 | 
 | 
 | 
 | process that | 
| 
 | 
 | 
 | 
 | 
 | modified the file | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[6] | Target of | String | “file=<full pathname>, | The full pathname | 
| 
 | 
 | Attack | 
 | mode=<mode>,uid=<uid>,gid=<gid>, | of the file and the | 
| 
 | 
 | 
 | 
 | file’s mode, uid, | |
| 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | inode=<inode>,device=<device>” | gid, inode, and | 
| 
 | 
 | 
 | 
 | 
 | device number | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[7] | Summary | String | Alert summary | |
| 
 | 
 | 
 | 
 | 
 | 
 | 
| Appendix A | 165 | 
