HP Host Intrusion Detection System (HIDS) Login/Logout Template, Table A-19 Template Properties

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 179
Image 179

Templates and Alerts

Login/Logout Template

 

Login/Logout Template

 

The vulnerability

There are certain privileged user accounts (such as adm, bin, sys) that are intended to be

addressed by this

used by system programs only for maintenance purposes. If these user accounts are

template

enabled and an attacker has compromised one of these user account passwords, the

 

system is vulnerable to being compromised by an attacker either logging into the system

 

as a privileged user or running the su command to assume the identity of a privileged

 

user.

 

 

How this template

The Login Logout template monitors for the start and end of interactive user sessions.

addresses the

Specifically, this template monitors sulog, wtmp on HP-UX 11i v1, and wtmps on HP-UX

vulnerability

11i v2 for the following:

 

 

 

• Successful remote logins whose utmp records are logged in utmp[s]

 

• Logouts

 

 

 

• Successful su commands to switch to another user name

How this template

This template supports the following properties:

is configured

The template can be configured to only monitor logins, only logouts, or only su attempts,

 

 

to monitor all of them or to monitor a subset of them (e.g., logins and su but not logouts).

 

The template can be configured to generate an alert if someone begins an interactive

 

session using a privileged user account such as adm, bin, sys, root, or ids and to ignore

 

all other users.

 

 

 

The template can also be configured to ignore logins and logouts by a small set of users

 

that are expected to be on the system during certain time periods and to generate alerts

 

for all other users. For example, on a database server, only the user dbmaint is expected

 

to login during a specified maintenance period. No other users are expected to be using

 

the system during that period. The template can be configured to generate an alert at

 

the start and end of remote connections by all users during the maintenance period

 

except for the dbmaint user.

 

 

Table A-19

Template Properties

 

 

 

 

 

 

 

 

Name

 

Type

Default Value

 

 

 

 

 

 

uids_to_ignore

 

III

<empty>

 

 

 

 

 

 

uids_to_monitor

 

III

<empty>

 

 

 

 

 

 

monitor_su_flag

 

VII

1

 

 

 

 

 

 

monitor_login_flag

 

VII

1

 

 

 

 

 

 

monitor_logout_flag

 

VII

1

 

 

 

 

 

 

ip_filters

 

V

<empty>

 

 

 

 

 

Appendix A

167

Page 179
Image 179
HP Host Intrusion Detection System (HIDS) manual Login/Logout Template, Table A-19 Template Properties