HP Host Intrusion Detection System (HIDS) manual Appendix a 177

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 189
Image 189

 

 

 

 

 

Templates and Alerts

 

 

 

 

Repeated Failed su Commands Template

Table A-25

Repeated Failed Su Attempts Alert Properties (Continued)

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Field

Alert Value/Format

Description

 

Field

 

Argument

Type

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[4]

UTC

Integer

<secs>

UTC time in number of

 

 

Time

 

 

seconds since epoch when

 

 

 

 

 

more than

 

 

 

 

 

<max_failed_su> number

 

 

 

 

 

of failed su attempts are

 

 

 

 

 

detected for a particular

 

 

 

 

 

user.

 

 

 

 

 

 

 

argv[5]

<empty>

n/a

User <username> had more than

This field is empty

 

 

 

 

<max_failed_su> failed su attempts

 

 

 

 

 

in the past <number> [second

 

 

 

 

 

minute hour day week]. Targets

 

 

 

 

 

were [ "<username>" "<username>"

 

 

 

 

 

.... ]

 

 

 

 

 

 

 

 

argv[6]

<empty>

n/a

n/a

This field is empty

 

 

 

 

 

 

 

argv[7]

Summary

String

“Failed su attempts”

Alert summary

 

 

 

 

 

 

 

argv[8]

Details

String

“User <username> had more than

Detailed alert description

 

 

 

 

<max_failed_su> failed su attempts

 

 

 

 

 

in the past <value> days. Targets

 

 

 

 

 

were ["username”,

 

 

 

 

 

 

 

 

argv[9]

Local

Integer

<secs>

Local time in number of

 

 

Time

 

 

seconds since epoch when

 

 

 

 

 

more than

 

 

 

 

 

<max_failed_su> number

 

 

 

 

 

of failed su attempts are

 

 

 

 

 

detected for a particular

 

 

 

 

 

user.

 

 

 

 

 

 

 

argv[10]

Flag

Integer

2

Indicates a failed su alert

 

 

 

 

 

versus a failed login alert

 

 

 

 

 

 

 

argv[11]

Device

String

<tty>

The tty from which a

 

 

 

 

 

failed su attempt was

 

 

 

 

 

made.

 

 

 

 

 

 

 

argv[12]

From

String

<username>

The name of the user

 

 

 

 

 

attempting to su.

 

 

 

 

 

 

 

argv[13]

To

String

<username>

The target user of the last

 

 

 

 

 

failed su attempt.

 

 

 

 

 

 

Limitations

None

 

 

 

Appendix A

177

Page 189
Image 189
HP Host Intrusion Detection System (HIDS) manual Appendix a 177