Host Intrusion Detection System Administrator's Guide Release 3.0

Templates and Alerts
Alert Summary
Appendix A
124
A file with world writable permission
was created by a privileged user, or
the world writable bit was set on an
existing file owned by a privileged
user, or the owner of a world writable
file was changed to a privileged user
from a non-privileged user, or a
world writable file owned by a
privileged user was renamed from a
location that is not being monitored
to a location that is being monitored
World writable file
created
3 Creation of
World-Writable File
Template
A file was truncated, deleted, or
renamed by a user other than the
owner of the file
Non-owned file being
modified
2 Modification of
Another User’s File
Template
A file’s mode or ownership was
modified by a user other than the
owner, or a file was opened for
modification by a user other than the
owner of the file.
Non-owned file being
modified
3 Modification of
Another User’s File
Template
A successful login as user "root" or
"ids"
Start of a successful
login session
2
a
Login/Logout
Template
A successful login as a user other
than "root" or "ids"
Start of a successful
login session
3
a
Login/Logout
Template
The logout of user "root" or "ids” End of a login session
2
Login/Logout
Template
The logout of a user other than "root"
or "ids"
End of a login session 3 Login/Logout
Template
A successful switch user (su) to
"root" or "ids"
Successful su session
2
Login/Logout
Template
A successful switch user (su) to a
user other than "root" or "ids"
Successful su session
3
Login/Logout
Template
Repeated attempts to login as user
"root" or "ids"
Failed login attempts 3 Repeated Failed
Logins Template
Repeated attempts to login as a user
other than "root" or "ids"
Failed login attempts 3 Repeated Failed
Logins Template
Repeated attempts to switch user to
"root" or "ids"
Failed su attempts 2 Repeated Failed su
Commands Template
Repeated attempts to switch user to
a user other than "root" or "ids"
Failed su attempts 3 Repeated Failed su
Commands Template
Table A-1 Detection Templates (Continued)
Attack Detected Alert Alert Severity Detection Template