A Unix Security Auditing System Based on Dynamic Tracing

XUE Zhi-ping,XUE Zhi,WANG Yi-jun
DOI: https://doi.org/10.3969/j.issn.1009-8054.2008.01.031
2008-01-01
Abstract:A Unix security auditing system based on dynamic tracing is described in this paper, and the design and realization are discussed. In the system, the detectors, set by dynamic tracing DTrace in the kernel, are used to collect audit information, and the audit logs are written in a standard format. Meanwhile, the secure storage and automatic analysis for the logs are realized in C/S mode.
What problem does this paper attempt to address?