|
|
|
| Automated Response | |
|
|
|
| How Automated Response Works in | |
Table | Additional Arguments Passed to Response Programs (Continued) | ||||
|
|
|
|
| |
Response | Alert | Alert | Alert |
| |
Program | Value/For | Description | |||
Field | Field Type | ||||
Argument | mat |
| |||
|
|
| |||
|
|
|
|
| |
argv[20] | Target File | Integer | <uid> | Owner of file (uid) under attack | |
| Owner |
|
|
| |
|
|
|
|
| |
argv[21] | Target File | Integer | <gid> | Group of file (gid) under attack. | |
| Group |
|
|
| |
|
|
|
|
| |
argv[22] | Target File | Integer | <inode> | Inode number of file under attack. | |
| Inode |
|
|
| |
|
|
|
|
| |
argv[23] | Target File | Integer | <device> | Device number of file under attack. | |
| Device |
|
|
| |
|
|
|
|
| |
argv[24] | Pathname | String | <full | Full pathname of attack program. | |
| of attack |
| pathname |
| |
| program |
| > |
| |
|
|
|
|
| |
argv[25] | Attack | Integer | <type> | File type of attack program. Corresponds to an | |
| Program |
|
| enum vtype value defined in vnode.h. | |
| Type |
|
|
| |
|
|
|
|
| |
argv[26] | Attack | Integer | <mode> | Mode of attack program. | |
| Program |
| (decimal) |
| |
| Mode |
|
|
| |
|
|
|
|
| |
argv[27] | Attack | Integer | <uid> | Owner of attack program (uid). | |
| Program |
|
|
| |
| Owner |
|
|
| |
|
|
|
|
| |
argv[28] | Attack | Integer | <gid> | Group of attack program (gid). | |
| Program |
|
|
| |
| Group |
|
|
| |
|
|
|
|
| |
argv[29] | Attack | Integer | <inode> | Inode number of attack program. | |
| Program |
|
|
| |
| Inode |
|
|
| |
|
|
|
|
| |
argv[30] | Attack | Integer | <device> | Device number of attack program. | |
| Program |
|
|
| |
| Device |
|
|
| |
|
|
|
|
| |
argv[31] | Attack | Integer | <argc> | Number of arguments passed to attack program | |
| Program |
|
| (e.g., argc). | |
| Argument |
|
|
| |
| Count |
|
|
| |
|
|
|
|
| |
argv[32] | Attack | String | <argv[0]> | Program arguments of attack program (first | |
| Program |
| <argv[1]> | 1024 characters). | |
| Arguments |
| ... |
| |
|
|
|
|
|
For the Race Condition template, the following additional arguments are passed to a response program:
Appendix B | 187 |