Automated Response

 

 

 

 

How Automated Response Works in HP-UX HIDS

Table B-1

Additional Arguments Passed to Response Programs (Continued)

 

 

 

 

 

Response

Alert

Alert

Alert

 

Program

Value/For

Description

Field

Field Type

Argument

mat

 

 

 

 

 

 

 

 

 

argv[20]

Target File

Integer

<uid>

Owner of file (uid) under attack

 

Owner

 

 

 

 

 

 

 

 

argv[21]

Target File

Integer

<gid>

Group of file (gid) under attack.

 

Group

 

 

 

 

 

 

 

 

argv[22]

Target File

Integer

<inode>

Inode number of file under attack.

 

Inode

 

 

 

 

 

 

 

 

argv[23]

Target File

Integer

<device>

Device number of file under attack.

 

Device

 

 

 

 

 

 

 

 

argv[24]

Pathname

String

<full

Full pathname of attack program.

 

of attack

 

pathname

 

 

program

 

>

 

 

 

 

 

 

argv[25]

Attack

Integer

<type>

File type of attack program. Corresponds to an

 

Program

 

 

enum vtype value defined in vnode.h.

 

Type

 

 

 

 

 

 

 

 

argv[26]

Attack

Integer

<mode>

Mode of attack program.

 

Program

 

(decimal)

 

 

Mode

 

 

 

 

 

 

 

 

argv[27]

Attack

Integer

<uid>

Owner of attack program (uid).

 

Program

 

 

 

 

Owner

 

 

 

 

 

 

 

 

argv[28]

Attack

Integer

<gid>

Group of attack program (gid).

 

Program

 

 

 

 

Group

 

 

 

 

 

 

 

 

argv[29]

Attack

Integer

<inode>

Inode number of attack program.

 

Program

 

 

 

 

Inode

 

 

 

 

 

 

 

 

argv[30]

Attack

Integer

<device>

Device number of attack program.

 

Program

 

 

 

 

Device

 

 

 

 

 

 

 

 

argv[31]

Attack

Integer

<argc>

Number of arguments passed to attack program

 

Program

 

 

(e.g., argc).

 

Argument

 

 

 

 

Count

 

 

 

 

 

 

 

 

argv[32]

Attack

String

<argv[0]>

Program arguments of attack program (first

 

Program

 

<argv[1]>

1024 characters).

 

Arguments

 

...

 

 

 

 

 

 

For the Race Condition template, the following additional arguments are passed to a response program:

Appendix B

187

Page 199
Image 199
HP Host Intrusion Detection System (HIDS) manual Appendix B 187