Schedule Manager Screen

Predefined Surveillance Schedules and Groups

Predefined Surveillance Schedules and Groups

Table 5-1 lists the predefined surveillance schedules and surveillance groups that are supplied with the system and the detection templates that they use.

The predefined surveillance schedules and groups, distributed with HP-UX HIDS, are read-only. They may be copied but not resaved or deleted. If you modify one, you can only save the changes under a new name.

All the groups use the default values for the properties of the templates. They have different timetables in different schedules. The templates, their properties, and their default values are described in detail in Appendix A, “Templates and Alerts,” on page 121.

Table 5-1

Predefined Surveillance Schedules

 

 

 

 

Surveillance Schedules

Surveillance Groups

Detection Templates

 

 

 

FileAndLoginMonitoringAlwaysOn

FileModificationGroup

Changes to Log File Template

 

 

 

Creation of Setuid File Template

 

 

 

Creation of World-Writable File

 

 

 

Template

 

 

 

Modification of Another User’s File

 

 

 

Template

 

 

 

Modification of Files/Directories

 

 

 

Template

 

 

 

 

 

 

LoginMonitoringGroup

Login/Logout Template

 

 

 

Repeated Failed Logins Template

 

 

 

Repeated Failed su Commands

 

 

 

Template

 

 

 

 

FileLoginMixture

 

FileModificationGroup

Changes to Log File Template

 

 

 

Creation of Setuid File Template

 

 

 

Creation of World-Writable File

 

 

 

Template

 

 

 

Modification of Another User’s File

 

 

 

Template

 

 

 

Modification of Files/Directories

 

 

 

Template

 

 

 

 

 

 

LoginMonitoringGroup

Login/Logout Template

 

 

 

Repeated Failed Logins Template

 

 

 

Repeated Failed su Commands

 

 

 

Template

 

 

 

 

Chapter 5

81

Page 93
Image 93
HP Host Intrusion Detection System (HIDS) manual Predefined Surveillance Schedules and Groups