An Enhanced Security Auditing Mechanism for Linux

徐辉,潘爱民
DOI: https://doi.org/10.3969/j.issn.1001-3695.2004.11.052
2004-01-01
Abstract:An enhanced security auditing mechanism for Linux is proposed.This mechanism is based on loadable kernel mo-(dule) and provides system level and application level auditing functions.System audit generates an audit record for every security sensitive system call.Application level audit abandons the traditional auditing fashion that auditing system completely depends on applications writing log file in user space.Instead,applications and system kernel will generate audit record coordinately.Examples are given for intrusion detection with this mechanism.
What problem does this paper attempt to address?