Re: New rules for su root attempts
Steve Grubb <[email protected]> Thu, 24 Jul 2008 14:34:10 -0400
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, I blew this. :) Corrected below On Thursday 24 July 2008 12:32:39 Steve Grubb wrote: > Authentication, authorization, session open failures all have different > meaning. Failure in Authentication could be brute forcing, Failure in > Authorization could be someone that stole the password and are now trying to > get in from a remote location. Failure in Session open is usually a resource > problem not of the user's making. > I'd like to describe both broadly and specifically what an event means so > that it can be used in more ways. What I mean by the above is somethings like "general.fine" as the event category. Where general can be big broad categories that abstract the event's specific's away, while fine could give very specific meaning. So you could have some thing like: authentication.login or authentication.credentials where both describe that authentication was done, but in one case it was a login, the other is su. I think the only way to enforce consistency is by API where you use a define that looks up the exact text and substitutes it. -Steve _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel