HP Host Intrusion Detection System (HIDS) manual Appendix a 165

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 177
Image 177

Templates and Alerts

Modification of Another User’s File Template

Table A-18

Non-owned File Being Modified Alert Properties (Continued)

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Alert Value/Format

Description

 

Field

Field Type

 

Argument

 

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[4]

UTC Time

Integer

<secs>

UTC time in

 

 

 

 

 

number of seconds

 

 

 

 

 

since epoch when

 

 

 

 

 

a file is modified

 

 

 

 

 

by a non-owner

 

 

 

 

 

 

 

argv[5]

Attacker

String

“uid=<uid>, gid=<gid>, pid=<pid>,

The user ID, group

 

 

 

 

ppid=<ppid>”

ID, process ID,

 

 

 

 

 

and parent

 

 

 

 

 

process ID of the

 

 

 

 

 

process that

 

 

 

 

 

modified the file

 

 

 

 

 

 

 

argv[6]

Target of

String

“file=<full pathname>,

The full pathname

 

 

Attack

 

mode=<mode>,uid=<uid>,gid=<gid>,

of the file and the

 

 

 

 

file’s mode, uid,

 

 

 

 

 

 

 

 

 

inode=<inode>,device=<device>”

gid, inode, and

 

 

 

 

 

device number

 

 

 

 

 

 

 

argv[7]

Summary

String

“Non-owned file being modified”

Alert summary

 

 

 

 

 

 

Appendix A

165

Page 177
Image 177
HP Host Intrusion Detection System (HIDS) manual Appendix a 165