引用本文:汪立东,方滨兴.Linux Shell安全审计机制的扩展.软件学报,2002,13(1):80-84
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4931次   下载 7483 本文二维码信息
码上扫一扫!
分享到: 微信 更多
Linux Shell安全审计机制的扩展
汪立东1, 方滨兴1
哈尔滨工业大学,计算机科学与技术学院,黑龙江,哈尔滨,150001
摘要:
Unix Shell生成的命令历史记录是系统审计信息的重要来源,但它未能包含检测入侵所需的足够信息,且容易被用户本人篡改.利用可装入内核模块和系统调用劫持技术实现了对Linux Shell安全审计机制的扩展,并给出了用其进行安全监测的例子.
关键词:  安全  审计  Linux可装入内核模块
DOI:
分类号:
基金项目:
An Extension to Security Auditing Mechanism of Linux Shell
WANG Li-dong,WANG Li-dong
Abstract:
Command history records generated by Unix shell is one of the important sources of system auditing information. But command history does not include sufficient information for intrusion detection and the history records can be easily modified by user themselves. With Linux loadable kernel module technique and system call interception, an extension to security auditing mechanism of Linux shell is implemented in this paper, and then some examples are given for security monitoring with the new mechanism.
Key words:  security  audit  Linux loadable kernel module

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: