15.07.2013 Views

Computer Security Threat Monitoring and Surveillance

Computer Security Threat Monitoring and Surveillance

Computer Security Threat Monitoring and Surveillance

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

S.l Relevant SMF Records<br />

5. Adapting to SMF Data<br />

The principal SMF records of use in performing the kind of auditing<br />

discussed in the preceding sections are record types 4, 5, 6, 10, 14,<br />

15, 17, 18, 20, 25, 26, 34, 35, 40, 62, 63, 64, 67, 68, 69, SO <strong>and</strong> Sl.<br />

Ordinarily, these record types would be the records making up the<br />

details of a particular job or use of a computer. In producing the<br />

audit flow, selection parameters such as user names can be used to<br />

extract all audit trail data with that user name associated with<br />

it to provide input to the audit record sort step which collects<br />

together in one place all record types associated with a particular<br />

job or use of a computer. The output of sorted job records is<br />

used as input-to a job summary or session summary record builder.<br />

It is the summary record builder program that would provide the<br />

essential information from which the audit history records would<br />

be created <strong>and</strong> maintained.<br />

When dealing with SMF, one is overwhelmed with data, a good deal<br />

of:.it..not necessarily useful for sec.urity audit purposes. A basic<br />

audit history record is shown in Figure 10. This record is the one<br />

used in the model program. The individual data items are self-explana­<br />

tory for the most part. The items indicated in square brackets<br />

are additional information available from SMF records that was not<br />

available in the accounting data in the model system.<br />

Where the record shows sessions, one could substitute the notion<br />

of jobs; aside from that, the history records characterize a particular<br />

use of the computer system in which the model was being developedo

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!