Re: New rules for su root attempts

Steve Grubb <[email protected]> Thu, 24 Jul 2008 14:34:10 -0400
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
Hi,

I blew this. :)  Corrected below

On Thursday 24 July 2008 12:32:39 Steve Grubb wrote:
> Authentication, authorization, session open failures all have different
> meaning. Failure in Authentication could be brute forcing, Failure in
> Authorization could be someone that stole the password and are now trying to
> get in from a remote location. Failure in Session open is usually a resource
> problem not of the user's making. 

> I'd like to describe both broadly and specifically what an event  means so
> that it can be used in more ways. 

What I mean by the above is somethings like "general.fine" as the event 
category. Where general can be big broad categories that abstract the event's 
specific's away, while fine could give very specific meaning. So you could 
have some thing like:  authentication.login or authentication.credentials 
where both describe that authentication was done, but in one case it was a 
login, the other is su.

I think the only way to enforce consistency is by API where you use a define 
that looks up the exact text and substitutes it.

-Steve


_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.