audit daemon 1.7.3 (Default branch) |
|
|
The audit package contains the user-space
utilities for creating audit rules, as well as for
storing and searching the audit records generate
by the audit subsystem in the Linux 2.6 kernel. It also has a basic Intrusion Detection plugin based on audit events capable of IDMEF alerting using prelude.
License: GNU General Public License (GPL)
Changes:
libauparse iteration bugs were fixed. Path name
processing is done in avc alerts. Key formatting
is done in ausearch. mmap page 0 alert was added
for the prelude plugin. audispd now has a separate
priority boost configuration option.
|